Query
Endpoint login activity across corporate devices
LogScale · Infrastructure · v1 · @sebastian · 30.7.2026
This query shows endpoint login events collected from corporate Windows laptops throughout the day. The log data includes device identifiers, hardware information, usernames, and login timestamps, providing visibility into user authentication activity across the managed workstation fleet. You can also exclude additional usernames. This query is based on the Falcon Data Replicator repository.
AuthenticationEndpointInvestigation
Query contentv1
Download v1Loading editor…
Version history
Every save keeps the previous content. Open any version to view or download it.