Skip to content

Commit fb41db9

Browse files
authored
Update o365_sharepoint_suspicious_search_behavior.yml
1 parent 0adf977 commit fb41db9

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/cloud/o365_sharepoint_suspicious_search_behavior.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ drilldown_searches:
3232
earliest_offset: $info_min_time$
3333
latest_offset: $info_max_time$
3434
- name: Investigate search behavior by $user$
35-
search: '`o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* AND UserId = $user|s$'
35+
search: '`o365_management_activity` Workload=SharePoint Operation="SearchQueryPerformed" SearchQueryText=* EventData=*search* AND UserId = "$user$"'
3636
earliest_offset: $info_min_time$
3737
latest_offset: $info_max_time$
3838
tags:

0 commit comments

Comments
 (0)