Security Support Common adds the following tables.
Table 1. Tables installed with Security Operations Common Support
Table Description
Additional Filter Group Condition


Contains conditions associated with filter groups. Filter groups can have multiple conditions associated with a single filter group.
Email Parser


Indicates how to parse email events into records.
Duplication Action


When an email rule is set to ‘Update duplicate record’, defines the actions that should take place to update the record.
Duplication Rule


Defines rules on how to define and handle duplicate records created using the email parser.
Enrichment Data


Enrichment table containing basic information gathered during a specific enrichment process.
Enrichment Data Mapping


Table that holds the enrichment mappings.
Enrichment Data Mapping Base


Base table for specific enrichment tables, holds general fields that are common among different enrichments. Only used for table inheritance (for example sn_si_network_statistics).
Enrichment Data Mapping Field


A field mapping for the enrichment process.


Defines an escalation group for security incidents.
Exchange Search


Groups different search criteria.
Exchange Search Criteria


Search Criteria that builds the query to search / delete emails in Exchange Server.
Exchange Search Result


Saves output returned from the Exchange server.
Field Mapping


Maps the results of a data enrichment integration to the data enrichment tables.
Field Mapping Field


Specifies the mapping from integration result names to the appropriate data enrichment table column.
Field Transform


Defines where to find the value for a field within an email in email processing.
Filter Group


Creates a generic group for any table type.
Integration Data Source


Imports threat and vulnerability data from external sources by associating the retrieved data with a data source.
Integration Data Source Import Queue Entry


Imports queue entries for importing threat and vulnerability information from external sources.
Integration Item Category


List of available integration categories (such as end point protection, firewall, vulnerability scanner).
Integration Item Configuration


Contains values used to support integrations (such as username, password, or API key).
Integration Process


Holds information about a single step in the execution of an integration run. Some integration runs may include multiple process steps.
Integration Run


Keeps track of attempts to execute an integration. Stores information about the specific integration attempt.
Manually Added Records


Configures lists of non-CI and non-task records belonging to a filter group.
Manually Added CI


Configures lists of CIs belonging to a filter group.
Manually Added Tasks


Configures lists of tasks belonging to a filter group.
Rate limit


Defines a rate limit to be used on a lookup source or scanner.


A threat lookup or vulnerability scan. Contains what to look up or scan, with what lookup source or scanner, and a summary of the results.
Scan Queue Entry


A threat lookup or vulnerability scan record queued for lookup, scan, or processing. Facilitates the requests within stated rate limits.


Defines third-party lookup source or scanners to use in lookups or scans.
Scanner Rate Limit


Associates a lookup source or scanner with a rate limit.
Security Calculator


Contains security calculators which belong to a group, and the order in which they are executed in the group.
Security Calculator Group


Groups security calculators by criteria.
Security Data Integration


Holds all available security integrations.
Security Email Events


Incoming email events, used to trigger email processing.
Security Integration Item


Information about all the available security integrations.
Security Operations Rate Limit


Parent table for rate limits, used by threat scanning and vulnerability scanning.
Security Operations Widgets


Generates data for dashboard widgets.
Simple REST Integration


Supports scheduled integration to external security tools via REST.
Workflow Triggers


Defines conditions by which to launch workflows.
Workflow Triggers Workflow


Associates workflows with workflow triggers.