Skip to content

Commit 1f18beb

Browse files
Update rules/integrations/azure/credential_access_azure_entra_susp_device_code_signin.toml
Co-authored-by: Terrance DeJesus <[email protected]>
1 parent 8fe958a commit 1f18beb

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

rules/integrations/azure/credential_access_azure_entra_susp_device_code_signin.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,7 @@ from logs-azure.signinlogs-* metadata _id, _version, _index
7979
Esql.non_interactive_logon = CASE(azure.signinlogs.category == "NonInteractiveUserSignInLogs", source.ip, null)
8080
8181
| stats Esql.count.logon = count(*),
82+
Esql.timestamp_values = values(@timestamp),
8283
Esql.dc.source_ip = count_distinct(source.ip),
8384
Esql.is_interactive = count(Esql.interactive_logon),
8485
Esql.is_non_interactive = count(Esql.non_interactive_logon),

0 commit comments

Comments
 (0)