The preceding query returns a list of the various types of data in your workspace. A cursory review of the various data types could easily indicate which types of data are related to security, as shown in the following screenshot. However, the Security and Audit solution makes use of various other data types in the list, including (but not limited to) Wire Data, DnsEvents, W3CIISLog, and Update:
The Security and Audit solution works with data collected from Windows Security Event logs, firewall logs, and AppLocker logs on Windows machines. On cross-platform machines, OMS collects security data from Syslog.
Examples ...