Hello,
looks like Microsoft Graph Security add all tags to all event type so its not correctly CIM mapped , any one filtered events based on alerts data and map to correct data models?
for example i need to sort out based on events and map to below data models
Malware - IDS - Endpoint - Alert
Thx