Rule Synopsis
These are the rule/s that determine the target CMDB CI Tables/Classes used by CI Sync for each MS Defender for Endpoint Asset Type.
The target CI Table/CI Class is used by CI Sync for two purposes:
-
To search for an existing CIs during a CI Update Operation.
-
To write new CIs during a CI Insert Operation.
Rule Details and Default
The default table mappings for Primary/Parent Resource Types are shown below.
|
Primary/Parent Resource Types |
Default Target Class/Classes |
|---|---|
|
Resources |
|
|
Apple Macs |
cmdb_ci_computer |
|
Windows PCs |
cmdb_ci_computer |
|
Windows Servers |
cmdb_ci_win_server |
The default table mappings for Secondary/Child Records are shown below.
|
Secondary/Child Records |
Default Target Class |
|---|---|
|
Software Installs |
cmdb_software_instance |
|
Vulnerabilities |
u_cisync_ci_cve#1 |
Footnote #1
Custom Tables are added via an Updateset provided by Syncfish. Please refer to the setup instructions Add MS Defender for Endpoint for more information.
Override Options
Context
Customers may consider changing these mappings to target different CMDB CI Tables/Classes shown above. This can often be required when existing CIs are already present in the CMDB (in Classes different to those shown below) and CI Sync is expected to correlate to the existing CIs.
Options
-
The target CI Class can be amended per Asset Type.
-
The target Related List/Child Record table can be amended per Asset Type.
Overriding via Connection Settings
Not Available - Requires a Custom Data Sync Rule (and therefore a Syncfish Support Plan to modify the default behaviour)
Additional Information
N/A