Forum Discussion

marwedit's avatar
marwedit
Copper Contributor
Jan 23, 2020
Solved

Log Analytics query filter select multiple accounts

Hi,   I want to setup a query and create an alert for (failed) signin attempts of multiple service accounts. I collect the signin attempts in Log Analytics and use this query to filter:   SigninL...
  • hspinto's avatar
    hspinto
    Jan 24, 2020

    marwedit, you just have to add a different condition to the query:

     

    SigninLogs

    | where OperationName == "Sign-in activity" and (UserPrincipalName in~ ('auobrien.david@outlook.com','john.doe@outlook.com','mary.jones@outlook.com') or UserPrincipalName startswith "svc_")

     

    See here a full list of the string operators you can use.

     

    Hope that helps!

Resources