Jan 07 2022 04:00 AM
Hi all,
Im hoping that there is someone in here who can help me write a query to display Outbound Transfer of over 20MB
Iv searched the Github community but cannot find anything on there like this query.
Thanks
Jan 07 2022 04:34 AM
Jan 07 2022 06:26 AM
let maxBytes = 20000000; //20MB
CommonSecurityLog
| where DeviceVendor == "Cisco"
| where DeviceProduct == "Firepower"
| extend bytesOut = extract('bytesOut=([^;]+)',1,AdditionalExtensions)
| where toreal(bytesOut) > maxBytes
Jan 07 2022 06:42 AM
Jan 07 2022 07:01 AM - edited Jan 07 2022 07:13 AM
SolutionMaybe this will help? The columns RequestURL and SourceUserName have some outbound context but not always (in my limited data set at least)
let maxBytes = 20971520; //20MB - from Bytes (B) Binary
CommonSecurityLog
| where DeviceVendor == "Cisco"
| where DeviceProduct == "Firepower"
| extend bytesOut = extract('bytesOut=([^;]+)',1,AdditionalExtensions)
| where toreal(bytesOut) > maxBytes
| extend MBytesOut = toreal(bytesOut)/1024/1024
| summarize by MBytesOut, RequestURL, SourceUserName , DestinationIP, DestinationPort
Jan 07 2022 08:25 AM
Jan 07 2022 08:47 AM