Update IPEntity_AppServiceHTTPLogs.yaml

Fixing Cip --> CIp on join condition.
This commit is contained in:
Shain 2020-12-19 08:41:59 -08:00 коммит произвёл GitHub
Родитель bff116a518
Коммит 36bccd7ef4
Не найден ключ, соответствующий данной подписи
Идентификатор ключа GPG: 4AEE18F83AFDEB23
1 изменённых файлов: 1 добавлений и 1 удалений

Просмотреть файл

@ -40,7 +40,7 @@ query: |
// renaming time column so it is clear the log this came from
| extend AppService_TimeGenerated = TimeGenerated
)
on $left.TI_ipEntity == $right.Cip
on $left.TI_ipEntity == $right.CIp
| summarize LatestIndicatorTime = arg_max(TimeGenerated, *) by IndicatorId
| project LatestIndicatorTime, Description, ActivityGroupNames, IndicatorId, ThreatType, Url, ExpirationDateTime, ConfidenceScore, AppService_TimeGenerated, TI_ipEntity, CsUsername, WebApp = split(_ResourceId, '/')[8], CIp, CsHost, NetworkIP, NetworkDestinationIP, NetworkSourceIP, EmailSourceIpAddress
| extend timestamp = AppService_TimeGenerated, AccountCustomEntity = CsUsername, IPCustomEntity = CIp, URLCustomEntity = CsHost