Forum Discussion

Jason Skaife's avatar
Jason Skaife
Copper Contributor
Jan 07, 2022

Sentinel Query

Hi all,   Im hoping that there is someone in here who can help me write a query to display Outbound Transfer of over 20MB   Iv searched the Github community but cannot find anything on there like...
  • Clive_Watson's avatar
    Clive_Watson
    Jan 07, 2022

    Jason Skaife 

    Maybe this will help?  The columns RequestURL and SourceUserName have some outbound context but not always (in my limited data set at least)

     

     

    let maxBytes = 20971520; //20MB - from Bytes (B) Binary
    CommonSecurityLog
    | where DeviceVendor == "Cisco"
    | where DeviceProduct == "Firepower"
    | extend bytesOut = extract('bytesOut=([^;]+)',1,AdditionalExtensions)
    | where toreal(bytesOut) > maxBytes
    | extend MBytesOut = toreal(bytesOut)/1024/1024
    | summarize by MBytesOut, RequestURL, SourceUserName , DestinationIP, DestinationPort

     

     

     

Share