Share via


AADNonInteractiveUserSignInLogs 數據表的查詢

具有多個城市的使用者

取得過去一天從多個城市登入的用戶清單。

AADNonInteractiveUserSignInLogs
| where TimeGenerated > ago(1d)
| extend City = parse_json(LocationDetails).city
| summarize CountPerCity = dcount(tostring(City)) by UserId
| where CountPerCity > 1
| order by CountPerCity desc

大部分作用中的IP位址

取得過去一天前 100 個最作用中 IP 位址的清單。

AADNonInteractiveUserSignInLogs
| where TimeGenerated > ago(1d)
| summarize CountPerIPAddress = count() by IPAddress
| order by CountPerIPAddress desc
| take 100