Skip to content

Latest commit

 

History

History
31 lines (28 loc) · 590 Bytes

SupressionRuleCreations.md

File metadata and controls

31 lines (28 loc) · 590 Bytes

List supression rule creations

Query Information

Description

This query lists supression rule creations.

Defender XDR

CloudAppEvents
| where ActionType == "Write AlertsSuppressionRules"
| project
     Timestamp,
     ActionType,
     Application,
     AccountId,
     AccountDisplayName,
     CreatedSupresionRule = ObjectName

Sentinel

CloudAppEvents
| where ActionType == "Write AlertsSuppressionRules"
| project
     TimeGenerated,
     ActionType,
     Application,
     AccountId,
     AccountDisplayName,
     CreatedSupresionRule = ObjectName