Skip to content

Commit f54500e

Browse files
authored
Standardize hyphen usage and fixed alignment of images
1 parent 83d7066 commit f54500e

File tree

1 file changed

+20
-20
lines changed

1 file changed

+20
-20
lines changed

CloudAppSecurityDocs/activity-filters-queries.md

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -70,41 +70,41 @@ Below is a list of the activity filters that can be applied. Most filters suppor
7070
- Tor exit nodes
7171
- Zscaler
7272

73-
- Impersonated activity Search only for activities that were performed in the name of another user.
73+
- Impersonated activity - Search only for activities that were performed in the name of another user.
7474

7575
- Instance - The app instance where the activity was or wasn't performed.
7676

77-
- Location The country/region from which the activity was performed.
77+
- Location - The country/region from which the activity was performed.
7878

79-
- Matched Policy Search for activities that matched a specific policy that was set in the portal.
79+
- Matched Policy - Search for activities that matched a specific policy that was set in the portal.
8080

81-
- Registered ISP The ISP from which the activity was performed.
81+
- Registered ISP - The ISP from which the activity was performed.
8282

8383
- Source - Search by the source from which the activity was detected. The source can be any of the following:
84-
- App connector - logs coming directly from the app's API connector.
84+
- App connector - Logs coming directly from the app's API connector.
8585
- App connector analysis - Defender for Cloud Apps enrichments based on information scanned by the API connector.
8686

87-
- User The user who performed the activity, which can be filtered into domain, group, name, or organization. In order to filter activities with no specific user, you can use the 'is not set' operator.
87+
- User - The user who performed the activity, which can be filtered into domain, group, name, or organization. In order to filter activities with no specific user, you can use the 'is not set' operator.
8888
- User domain - Search for a specific user domain.
89-
- User organization The organizational unit of the user who performed the activity, for example, all activities performed by EMEA_marketing users. This is only relevant for connected Google Workspace instances using organizational units.
90-
- User group Specific user groups that you can import from connected apps, for example, Microsoft 365 administrators.
89+
- User organization - The organizational unit of the user who performed the activity, for example, all activities performed by EMEA_marketing users. This is only relevant for connected Google Workspace instances using organizational units.
90+
- User group - Specific user groups that you can import from connected apps, for example, Microsoft 365 administrators.
9191
- User name - Search for a specific username. To see a list of users in a specific user group, in the **Activity drawer**, select the name of the user group. Clicking will take you to the Accounts page, which lists all the users in the group. From there, you can drill down into the details of the accounts of specific users in the group.
9292
- The **User group** and **User name** filters can be further filtered by using the **As** filter and selecting the role of the user, which can be any of the following:
9393
- Activity object only - meaning that the user or user group selected didn't perform the activity in question; they were the object of the activity.
9494
- Actor only - meaning that the user or user group performed the activity.
9595
- Any role - Meaning that the user or user group was involved in the activity, either as the person who performed the activity or as the object of the activity.
9696

97-
- User agent The user agent of from with the activity was performed.
97+
- User agent - The user agent of from with the activity was performed.
9898

99-
- User agent tag Built-in user agent tag, for example, all activities from outdated operating systems or outdated browsers.
99+
- User agent tag - Built-in user agent tag, for example, all activities from outdated operating systems or outdated browsers.
100100

101101
## Activity queries
102102

103103
To make investigation even simpler, you can now create custom queries and save them for later use.
104104

105105
1. In the **Activity log** page, use the filters as described above to drill down into your apps as necessary.
106106

107-
:::image type="content" source="media/activity-log-query.png" alt-text="Use filters to make query.":::
107+
:::image type="content" source="media/activity-log-query.png" alt-text="Use filters to make query.":::
108108

109109
1. After you've finished building your query, select the **Save as** button.
110110

@@ -118,23 +118,23 @@ To make investigation even simpler, you can now create custom queries and save t
118118

119119
Defender for Cloud Apps also provides you with **Suggested queries**. Suggested queries provide you with recommended avenues of investigation that filter your activities. You can edit these queries and save them as custom queries. The following are optional suggested queries:
120120

121-
- Admin activities - filters all your activities to display only those activities that involve admins.
121+
- Admin activities - Filters all your activities to display only those activities that involve admins.
122122

123-
- Download activities - filters all your activities to display only those activities that were download activities, including downloading user list as a .csv file, downloading shared content, and downloading a folder.
123+
- Download activities - Filters all your activities to display only those activities that were download activities, including downloading user list as a .csv file, downloading shared content, and downloading a folder.
124124

125-
- Failed log-in - filters all your activities to display only failed sign-in and failed sign-ins via SSO
125+
- Failed log-in - Filters all your activities to display only failed sign-in and failed sign-ins via SSO
126126

127-
- File and folder activities - filters all your activities to display only those involving files and folders. The filter includes uploading, download, and accessing folders, along with creating, deleting, uploading, downloading, quarantining, and accessing files and transferring content.
127+
- File and folder activities - Filters all your activities to display only those involving files and folders. The filter includes uploading, download, and accessing folders, along with creating, deleting, uploading, downloading, quarantining, and accessing files and transferring content.
128128

129-
- Impersonation activities - filters all your activities to display only impersonation activities.
129+
- Impersonation activities - Filters all your activities to display only impersonation activities.
130130

131-
- Password changes and reset requests - filters all your activities to display only those activities that involve password reset, change password, and force a user to change the password on the next sign-in.
131+
- Password changes and reset requests - Filters all your activities to display only those activities that involve password reset, change password, and force a user to change the password on the next sign-in.
132132

133-
- Sharing activities - filters all your activities to display only those activities that involve sharing folders and files, including creating a company link, creating an anonymous link, and granting read/write permissions.
133+
- Sharing activities - Filters all your activities to display only those activities that involve sharing folders and files, including creating a company link, creating an anonymous link, and granting read/write permissions.
134134

135-
- Successful log-in - filters all your activities to display only those activities that involve successful sign-ins, including impersonate action, impersonate sign-in, single sign-o sign-ins, and sign-in from a new device.
135+
- Successful log-in - Filters all your activities to display only those activities that involve successful sign-ins, including impersonate action, impersonate sign-in, single sign-o sign-ins, and sign-in from a new device.
136136

137-
![query activities.](media/queries-activity.png)
137+
![query activities.](media/queries-activity.png)
138138

139139
Additionally, you can use the suggested queries as a starting point for a new query. First, select one of the suggested queries. Then, make changes as needed and finally select **Save as** to create a new **Saved query**.
140140

0 commit comments

Comments
 (0)