请求修正Azure Sentinel中用户单主机登录失败转成功的KQL告警查询
修正Azure Sentinel告警查询:检测同一主机上的登录失败后成功事件
原查询的核心问题是仅按用户(Account)维度聚合,导致跨主机的登录操作被合并统计,无法满足"同一主机"的检测要求。以下是修正后的KQL查询,已限定在同一用户+同一主机范围内检测先多次失败、后成功的登录行为:
let timeRange = 6h; let authenticationWindow = 1h; let authenticationThreshold = 15; SecurityEvent | where TimeGenerated > ago(timeRange) | where EventID == 4624 or EventID == 4625 | where IpAddress != "-" and isnotempty(Account) and AccountType == "User" | extend Outcome = iff(EventID == 4624, "Success", "Failure") // 按用户、主机、结果等维度聚合,同时对时间分箱优化统计精度 | summarize OutcomeCount=count() by Account, IpAddress, Computer, Outcome, WorkstationName, bin(TimeGenerated, 1m) | project TimeGenerated, Account, IpAddress, Computer, Outcome, OutcomeCount, WorkstationName // 按用户、主机、时间排序,确保序列逻辑准确 | sort by Account asc, Computer asc, TimeGenerated asc | serialize // 会话划分新增主机维度,仅同一用户+同一主机的操作归为同一会话 | extend SessionStartedUtc = row_window_session(TimeGenerated, timeRange, authenticationWindow, Account != prev(Account) or Computer != prev(Computer) or prev(Outcome) == "Success") // 按会话、用户、主机聚合,确保统计范围严格限定在单主机内 | summarize FailureCountBeforeSuccess=sumif(OutcomeCount, Outcome == "Failure"), StartTime=min(TimeGenerated), EndTime=max(TimeGenerated), OutcomeSequence=makelist(Outcome), IpAddress=makeset(IpAddress), WorkstationName=makeset(WorkstationName) by SessionStartedUtc, Account, Computer // 验证事件序列:成功登录不在开头,且是最后一个事件 | where array_index_of(OutcomeSequence, "Success") != 0 | where array_index_of(OutcomeSequence, "Success") == array_length(OutcomeSequence) - 1 | project-away SessionStartedUtc, OutcomeSequence // 过滤达到失败次数阈值的告警 | where FailureCountBeforeSuccess >= authenticationThreshold
关键修改说明:
- 会话维度锁定:在
row_window_session中加入Computer != prev(Computer)判断,确保会话仅包含同一用户在同一主机上的登录操作,彻底避免跨主机行为误统计。 - 聚合范围限定:最终
summarize时新增Computer作为分组键,所有统计逻辑(失败次数、时间范围等)都严格限定在单主机范围内。 - 时间精度优化:对
TimeGenerated按1分钟分箱,避免同一秒内的重复日志干扰统计,同时保留时间序列的准确性。
内容的提问来源于stack exchange,提问作者Sree ak
相关产品推荐
相关产品推荐

