Project Original Parameters
This commit is contained in:
Родитель
a3c3543abe
Коммит
cafc25756e
|
@ -31,7 +31,7 @@ query: |
|
|||
| where ExpandedParameters.Name in~ ("BlindCopyTo", "RedirectMessageTo") and isnotempty(ExpandedParameters.Value)
|
||||
| extend RedirectTo = ExpandedParameters.Value
|
||||
| extend ClientIPValues = extract_all(@'\[?(::ffff:)?(?P<IPAddress>(\d+\.\d+\.\d+\.\d+)|[^\]]+)\]?([-:](?P<Port>\d+))?', dynamic(["IPAddress", "Port"]), ClientIP)[0]
|
||||
| project TimeGenerated, RedirectTo, IPAddress = tostring(ClientIPValues[0]), Port = tostring(ClientIPValues[1]), UserId, Operation, RuleName, ParsedParameters
|
||||
| project TimeGenerated, RedirectTo, IPAddress = tostring(ClientIPValues[0]), Port = tostring(ClientIPValues[1]), UserId, Operation, RuleName, Parameters
|
||||
| extend timestamp = TimeGenerated, AccountCustomEntity = UserId, IPCustomEntity = IPAddress
|
||||
|
||||
entityMappings:
|
||||
|
|
Загрузка…
Ссылка в новой задаче