Security events are a special type of data representing security-relevant data generated by Dynatrace, but also third-party vendors. The security events models are organized into the following subcategories:
In the security.events table, the data is separated in different buckets, depending on the origin of the data. For Dynatrace generated data, data is stored in the default_securityevents_builtin bucket, data ingested through the ingest APIs is stored in the default_securityevents bucket, unless rerouted to another bucket in OpenPipeline.