The Advanced Security Information Model (ASIM) enables you to use and create source-agnostic content, simplifying your analysis of the data in your Microsoft Sentinel workspace.
For more information, see Normalization and the Advanced Security Information Model (ASIM)
GitHub Copilot agent skills are available to help you create, validate, deploy, and package ASIM parsers locally. The skills guide you through the full workflow — from gathering requirements and generating KQL parsers to deploying to Log Analytics and opening a PR.
See ASIM Parser Creation - Agentic to get started.
This template deploys all ASIM parsers.
To deploy a single schema use the buttons below:
| ASim Schema | Deploy | Deploy to Azure Gov |
|---|---|---|
| Alert Event | ||
| Audit Event | ||
| Authentication | ||
| Dhcp Event | ||
| Dns | ||
| File Event | ||
| Network Session | ||
| Process Event | ||
| Registry Event | ||
| UserManagement | ||
| Web Session |