mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update o365_email_hard_delete_excessive_volume.yml
This commit is contained in:
@@ -37,7 +37,7 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: message: The user $user$ deleted an excessing number of emails [$count$] within a short timeframe
|
||||
message: The user $user$ deleted an excessing number of emails [$count$] within a short timeframe
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
|
||||
Reference in New Issue
Block a user