Kusto Query LanguageMicrosoft Defender for EndpointMicrosoft SentinelSECURE

Visualize Top 100 Users That Have The Most Interactive Sign-ins

Description

This KQL query visualizes the top 100 users that have performed the most interactive sign ins.

Query

Microsoft Defender For Endpoint
Kusto
IdentityLogonEvents
| where LogonType == 'Interactive'
| where isempty(FailureReason)
| distinct AccountUpn, DeviceName
| summarize TotalUniqueInteractiveSignIns = count() by AccountUpn
| top 100 by TotalUniqueInteractiveSignIns
| render columnchart with (title="Top 100 users that have the most interactive sign ins")

Microsoft Sentinel
Kusto
IdentityLogonEvents
| where LogonType == 'Interactive'
| where isempty(FailureReason)
| distinct AccountUpn, DeviceName
| summarize TotalUniqueInteractiveSignIns = count() by AccountUpn
| top 100 by TotalUniqueInteractiveSignIns
| render columnchart with (title="Top 100 users that have the most interactive sign ins")

Leave a Reply

Your email address will not be published. Required fields are marked *