upd parser schema; fix rule query
This commit is contained in:
Родитель
85b356fbe1
Коммит
41417b3ec6
|
@ -5,6 +5,10 @@
|
|||
"Name": "AccessDvcBrowser",
|
||||
"Type": "String"
|
||||
},
|
||||
{
|
||||
"Name": "TimeGenerated",
|
||||
"Type": "DateTime"
|
||||
},
|
||||
{
|
||||
"Name": "AccessDvcBrowserVersion",
|
||||
"Type": "String"
|
||||
|
|
|
@ -21,7 +21,7 @@ query: |
|
|||
| where EventResult =~ 'success'
|
||||
| where isnotempty(AccessDvcIpAddr)
|
||||
| summarize dvc_ip = makeset(AccessDvcIpAddr) by DstUserName
|
||||
| extend k=1;
|
||||
| extend k=1
|
||||
join (CiscoDuo
|
||||
| where EventType =~ 'authentication'
|
||||
| where EventResult =~ 'success'
|
||||
|
|
Загрузка…
Ссылка в новой задаче