LogScale Queries

Query

Endpoint login activity across corporate devices

LogScale · Infrastructure · v1 · @sebastian · 30.7.2026

All Queries

This query shows endpoint login events collected from corporate Windows laptops throughout the day. The log data includes device identifiers, hardware information, usernames, and login timestamps, providing visibility into user authentication activity across the managed workstation fleet. You can also exclude additional usernames. This query is based on the Falcon Data Replicator repository.

AuthenticationEndpointInvestigation

Query contentv1

Download v1
Loading editor…

Version history

Every save keeps the previous content. Open any version to view or download it.

  1. v1current

    30.7.2026, 16:12:03