Path: blob/master/tutorials-and-examples/example-notebooks/data/data_queries.yaml
3255 views
metadata:1version: 12description: Local Data Alert Queries3data_environments: [LocalData]4data_families: [SecurityAlert, WindowsSecurity, Network, Azure]5tags: ['alert', 'securityalert', 'process', 'account', 'network', 'logon']6defaults:7metadata:8data_source: 'security_alert'9parameters:10sources:11list_alerts:12description: Retrieves list of alerts13metadata:14data_families: [SecurityAlert]15args:16query: alerts_list.pkl17parameters:18list_host_processes:19description: List processes on host20metadata:21data_families: [WindowsSecurity]22args:23query: processes_on_host.pkl24parameters:25list_host_logons:26description: List logons on host27metadata:28data_families: [WindowsSecurity]29args:30query: host_logons.pkl31parameters:32list_host_logon_failures:33description: List logon failures on host34metadata:35data_families: [WindowsSecurity]36args:37query: failed_logons.pkl38parameters:39list_host_events:40description: List events failures on host41metadata:42data_families: [WindowsSecurity]43args:44query: all_events_df.pkl45parameters:46get_process_tree:47description: Get process tree for a process48metadata:49data_families: [WindowsSecurity]50args:51query: process_tree.pkl52parameters:53list_azure_network_flows_by_ip:54description: List Azure Network flows by IP address55metadata:56data_families: [Network]57args:58query: az_net_comms_df.pkl59parameters:60list_azure_network_flows_by_host:61description: List Azure Network flows by host name62metadata:63data_families: [Network]64args:65query: az_net_comms_df.pkl66parameters:67list_all_signins_geo:68description: List all Azure AD logon events69metadata:70data_families: [Azure]71args:72query: aad_logons.pkl73parameters:7475