Skip to content

Commit 939d1bd

Browse files
authored
Merge pull request #11755 from Azure/shainw-fixMailItemsUrl
Update MailItemsAccessedTimeSeries.yaml
2 parents 03d2380 + 750d63d commit 939d1bd

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

Solutions/Microsoft 365/Analytic Rules/MailItemsAccessedTimeSeries.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ description: |
55
The query leverages KQL built-in anomaly detection algorithms to find large deviations from baseline patterns.
66
Sudden increases in execution frequency of sensitive actions should be further investigated for malicious activity.
77
Manually change scorethreshold from 1.5 to 3 or higher to reduce the noise based on outliers flagged from the query criteria.
8-
Read more about MailItemsAccessed- https://docs.microsoft.com/microsoft-365/compliance/advanced-audit?view=o365-worldwide#mailitemsaccessed'
8+
Read more about MailItemsAccessed- https://learn.microsoft.com/en-us/purview/audit-log-investigate-accounts'
99
severity: Medium
1010
status: Available
1111
requiredDataConnectors:
@@ -76,5 +76,5 @@ entityMappings:
7676
fieldMappings:
7777
- identifier: Address
7878
columnName: SourceIPMax
79-
version: 2.0.5
80-
kind: Scheduled
79+
version: 2.0.6
80+
kind: Scheduled

0 commit comments

Comments
 (0)