Jason Skaife
Jan 07, 2022Copper Contributor
Sentinel Query
Hi all, Im hoping that there is someone in here who can help me write a query to display Outbound Transfer of over 20MB Iv searched the Github community but cannot find anything on there like...
- Jan 07, 2022
Maybe this will help? The columns RequestURL and SourceUserName have some outbound context but not always (in my limited data set at least)
let maxBytes = 20971520; //20MB - from Bytes (B) Binary CommonSecurityLog | where DeviceVendor == "Cisco" | where DeviceProduct == "Firepower" | extend bytesOut = extract('bytesOut=([^;]+)',1,AdditionalExtensions) | where toreal(bytesOut) > maxBytes | extend MBytesOut = toreal(bytesOut)/1024/1024 | summarize by MBytesOut, RequestURL, SourceUserName , DestinationIP, DestinationPort