Skip to content

Commit 8fe958a

Browse files
Update rules/integrations/azure/credential_access_azure_entra_susp_device_code_signin.toml
Co-authored-by: Terrance DeJesus <[email protected]>
1 parent 1dc7607 commit 8fe958a

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules/integrations/azure/credential_access_azure_entra_susp_device_code_signin.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,7 @@ from logs-azure.signinlogs-* metadata _id, _version, _index
9090
Esql.source_ip_values = VALUES(source.ip) by azure.signinlogs.properties.session_id, azure.signinlogs.identity
9191
9292
| where Esql.is_interactive >= 2 and Esql.is_non_interactive >= 1 and (Esql.dc.source_ip >= 2 or Esql.dc.user_agents >= 2)
93-
| keep @timestamp,
93+
| keep
9494
Esql.*,
9595
azure.signinlogs.properties.session_id,
9696
azure.signinlogs.identity

0 commit comments

Comments
 (0)