Question on "Anomalous sign-in location by user account and authenticating application" query

%3CLINGO-SUB%20id%3D%22lingo-sub-1204280%22%20slang%3D%22en-US%22%3EQuestion%20on%20%22Anomalous%20sign-in%20location%20by%20user%20account%20and%20authenticating%20application%22%20query%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1204280%22%20slang%3D%22en-US%22%3E%3CP%3ETrying%20to%20determine%20if%20there%20is%20a%20need%20to%20modify%20the%20query%20as%20it%20states%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%2F%2FThe%20original%20alert's%20time-frame%20filter%2C%20which%20should%20be%20added%20to%20each%20table%20in%20the%20query%20is%3A%3C%2FP%3E%3CP%3E%2F%2F%22where%20TimeGenerated%20between%20(datetime(2%2F16%2F2020%205%3A43%3A38%20PM)..datetime(3%2F1%2F2020%205%3A43%3A38%20PM))%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20the%20query%20has%20a%20few%20%E2%80%9Cwhere%20TimeGenerated%E2%80%9D%20calls%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%7C%20where%20TimeGenerated%20%26gt%3B%3D%20startofday((datetime(3%2F1%2F2020%205%3A43%3A38%20PM)-(lookBack_long)))%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EShould%20these%20be%20changed%20to%2C%20%E2%80%9C%7C%20where%20TimeGenerated%20between%20(datetime(2%2F17%2F2020%207%3A00%3A00%20AM)..datetime(3%2F1%2F2020%207%3A00%3A00%20AM))%2C%20or%2C%20does%20%E2%80%9C-lookback_long%E2%80%9D%20cover%20the%2014%20day%20period%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1204359%22%20slang%3D%22en-US%22%3ERe%3A%20Question%20on%20%22Anomalous%20sign-in%20location%20by%20user%20account%20and%20authenticating%20application%26amp%3Bquot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1204359%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F173036%22%20target%3D%22_blank%22%3E%40Jeff%20Walzer%3C%2FA%3E-%20Never%20mind%20as%20I%20figured%20out%20I%20simply%20enter%20the%20date%20time%20range%20of%20when%20the%20event%20occurred%20to%20see%20the%20event%20the%20triggered%20the%20alert%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Trying to determine if there is a need to modify the query as it states:

 

//The original alert's time-frame filter, which should be added to each table in the query is:

//"where TimeGenerated between (datetime(2/16/2020 5:43:38 PM)..datetime(3/1/2020 5:43:38 PM))"

 

And the query has a few “where TimeGenerated” calls:

 

| where TimeGenerated >= startofday((datetime(3/1/2020 5:43:38 PM)-(lookBack_long)))

 

Should these be changed to, “| where TimeGenerated between (datetime(2/17/2020 7:00:00 AM)..datetime(3/1/2020 7:00:00 AM)), or, does “-lookback_long” cover the 14 day period?

1 Reply

@Jeff Walzer- Never mind as I figured out I simply enter the date time range of when the event occurred to see the event the triggered the alert