Closed
Description
The Analytics Rule: Preview - TI map IP entity to Cloud App Events
generates false positives if the MCAS column doesn't contain any IP address but due to the join null / empty values are matched.
Changing the join to remove empty MCAS IPs should resolve this:
| join kind=innerunique (
CloudAppEvents
// --> Remove empty IPs
| where isnotempty(IPAddress)
| where TimeGenerated >= ago(dt_lookBack)
| extend CloudAppEvents_TimeGenerated = TimeGenerated) on $left.TI_ipEntity == $right.IPAddress
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment