Azure-Sentinel/Playbooks/Export-Report-CSV/reportWatchlist.csv

392 B

1TitleScheduleQueryBodyRecipients
2Simple Export TestDailySigninLogs | where TimeGenerated >= ago(24h) | where UserPrincipalName == "amy@contoso.com"joe@contoso.com
3New Report!DailyAuditLogsjoe@contoso.com
4Bitlocker RecoveriesDailyAuditLogs | where OperationName == "Read BitLocker key" | extend userPrincipalName = initiatedBy.user.userPrincipalNamejoe@contoso.com