View Query Audit Logs in Microsoft Sentinel

  Рет қаралды 1,422

Samik Roy

Samik Roy

Күн бұрын

Пікірлер: 2
@sarathkumaras
@sarathkumaras Жыл бұрын
Hi bro, can you help me with a KQL query to know who has done a " role assignment" for a given user
@samikroy
@samikroy Жыл бұрын
This query might help you AuditLogs | where OperationName == "Add member to role" | extend Target = tostring(TargetResources[0].userPrincipalName) | extend RoleAdded = tostring(parse_json(tostring(parse_json(tostring(TargetResources[0].modifiedProperties))[1].newValue))) | extend Actor = tostring(parse_json(tostring(InitiatedBy.user)).userPrincipalName) | project TimeGenerated, OperationName, Actor, Target, RoleAdded
СОБАКА И  ТРИ ТАБАЛАПКИ Ч.2 #shorts
00:33
INNA SERG
Рет қаралды 2,1 МЛН
When u fight over the armrest
00:41
Adam W
Рет қаралды 17 МЛН
5 Excel Secrets You'll Be Embarrassed You Didn't Know
17:32
Excel Campus - Jon
Рет қаралды 235 М.
Enable Enrichment Widget Sentinel
5:11
Samik Roy
Рет қаралды 515
Microsoft Sentinel Integration | Virtual Ninja Training with Heike Ritter
31:23
Microsoft Security Community
Рет қаралды 3,3 М.
Azure Monitor Logs Log Types
29:30
John Savill's Technical Training
Рет қаралды 42 М.
Microsoft Sentinel Setup and Configuration
24:09
AzureVlog
Рет қаралды 28 М.
Intro to Microsoft Sentinel
4:46
T-Minus365
Рет қаралды 11 М.
How to use Microsoft Loop app
16:49
Kevin Stratvert
Рет қаралды 671 М.
Learn the Fundamentals of Microsoft Fabric in 38 minutes
38:00
Learn Microsoft Fabric with Will
Рет қаралды 184 М.
Microsoft Sentinel-Threat Hunting
5:44
T-Minus365
Рет қаралды 17 М.