LogScale Queries
Collector 1.11.5 · Release notes

LogScale Query Exchange

Share, discover, and version LogScale queries, parsers, dashboards, and how-tos with the community.

148 queries0 parsers2 dashboards0 how-tos1 contributors

Latest queries

Recently shared by the community.

View all →
query.txt
in(field="#windows.EventID", values=[4732,4728,4756,4729,4733,4757])
| day := formatTime(format="%Y-%m-%d", field=@timestamp, timezone="Europe/Berlin")
| rename(field="windows.EventData.TargetUserName", as="group")
| groupBy([day, group], function=count())

Aggregate Active Directory group membership additions and removals into a daily count by group for compliance reporting and anomaly baselining. Keep the timezone aligned with your investigation queries. Source: the blog article “5 LogScale queries to audit Active Directory group changes” — https://it-selig.de/blog/logscale-queries-ad-group-changes

LogScaleComplianceActiveDirectoryComplianceMonitoring

@sebastian · 2.8.2026

query.txt
in(field="#windows.EventID", values=[4732,4728,4756,4729,4733,4757])
| windows.EventData.SubjectUserName=/^(svc_|sa_|srv_)/i

// only show during office hours, when automation should be idle

Find group membership changes made by service accounts during the period when their automation should be idle. Adapt the account-name regex, office-hour window, and IANA timezone to match your conventions. Source: the blog article “5 LogScale queries to audit Active Directory group changes” — https://it-selig.de/blog/logscale-queries-ad-group-changes

LogScaleDetection & MonitoringActiveDirectoryDetectionMonitoring

@sebastian · 2.8.2026

query.txt
in(field="#windows.EventID", values=[4732,4728,4756])
| test(windows.EventData.MemberSid == windows.EventData.SubjectUserSid)

// format the table

Find Active Directory group additions where the requesting account and the added member share the same SID. These rare self-additions are a high-signal escalation pattern worth investigating. Source: the blog article “5 LogScale queries to audit Active Directory group changes” — https://it-selig.de/blog/logscale-queries-ad-group-changes

LogScaleDetection & MonitoringActiveDirectoryDetectionWindows

@sebastian · 2.8.2026

Latest parsers

Recently shared ingest parsers.

View all →

No parsers published yet.

Upload parser

Latest dashboards

Recently shared dashboard definitions.

View all →
dashboard.json
name: User Dashboard
timeSelector:
  defaultTimeJumpInMs: 30000
sharedTimeInterval:

Provides a centralized overview of user logins across virtual desktop environments. The dashboard links activity to specific desktop pools (e.g., Windows 7 and Windows 10) and tracks concurrent logins, enabling administrators to monitor users who are simultaneously accessing multiple pools. You can change the poolIds to match your environment.

DashboardEndpoint

@sebastian · 24.7.2026

Latest how-tos

Recently shared guides and walkthroughs.

View all →

No how-tos published yet.