admin管理员组文章数量:1334887
I am trying to create scheduled search in CrowdStrike, that will run a FQL which searches for all the users (that are not clients) that connected to system in our environment using RDP. I need a daily report for the users connected in the last 24 hours.
The condition is - they should be logged in remotely (I've used remote interactive option for this which is denoted by number 10), in our environment (I am using our environment's Cid), and they should be admin (used UserIsAdmin value as 1 that means 'Yes').
The query yields required results when I use it in the advanced event search, and I can also get this result in a dashboard I've created using the same values. But when I tested it in a scheduled search, I am not getting any result:
I basically need a result with these values, which can be sent to our team through email in a csv format:
Below is the query, I want some additional user information too so those are also mentioned:
本文标签: windowsCrowdStrike scheduled search is not yielding any resultsStack Overflow
版权声明:本文标题:windows - CrowdStrike scheduled search is not yielding any results - Stack Overflow 内容由网友自发贡献,该文观点仅代表作者本人, 转载请联系作者并注明出处:http://www.betaflare.com/web/1742380386a2463973.html, 本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌抄袭侵权/违法违规的内容,一经查实,本站将立刻删除。
发表评论