fixed AzureSentinelConnectors_Admin
This commit is contained in:
Родитель
d87febd45b
Коммит
7e8b2483bc
|
@ -18,7 +18,7 @@ query: |
|
|||
// Azure Sentinel Data Connectors Update / Delete
|
||||
AzureActivity
|
||||
| where TimeGenerated >= ago(timeframe)
|
||||
| where Category == "Administrative"
|
||||
| where CategoryValue == "Administrative"
|
||||
| where OperationNameValue in (opValues)
|
||||
| where ActivitySubstatusValue in ("Created", "OK")
|
||||
| sort by TimeGenerated desc
|
||||
|
|
Загрузка…
Ссылка в новой задаче