admin管理员组

文章数量:1334887

I am trying to create scheduled search in CrowdStrike, that will run a FQL which searches for all the users (that are not clients) that connected to system in our environment using RDP. I need a daily report for the users connected in the last 24 hours.

The condition is - they should be logged in remotely (I've used remote interactive option for this which is denoted by number 10), in our environment (I am using our environment's Cid), and they should be admin (used UserIsAdmin value as 1 that means 'Yes').

The query yields required results when I use it in the advanced event search, and I can also get this result in a dashboard I've created using the same values. But when I tested it in a scheduled search, I am not getting any result:

I basically need a result with these values, which can be sent to our team through email in a csv format:

Below is the query, I want some additional user information too so those are also mentioned:

本文标签: windowsCrowdStrike scheduled search is not yielding any resultsStack Overflow