LogScale Queries

Category

Infrastructure

Servers, cloud resources, Kubernetes, and platform health.

1 published query

query.txt
#event_simpleName=UserLogon
| UserName!=/^DWM-/i
| UserName!=/^UMFD-/i
| UserName!=/^Lokaler Dienst/i

This query shows endpoint login events collected from corporate Windows laptops throughout the day. The log data includes device identifiers, hardware information, usernames, and login timestamps, providing visibility into user authentication activity across the managed workstation fleet. You can also exclude additional usernames. This query is based on the Falcon Data Replicator repository.

LogScaleInfrastructureAuthenticationEndpointInvestigation

@sebastian · 30.7.2026