-
Notifications
You must be signed in to change notification settings - Fork 468
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[google_workspace] Missing extra filters for Successful Logins by Compromised Users
panel
#8745
Comments
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
@ebeahan to clarify. We have events for suspending users. We have events to identify compromised devices. This ticket appears to be asking for a filter that: |
@marc-gr mentioned that there is a is_suspicious flag on logins. Perhaps filtering by this flag is what the goal is? |
@StacieClark-Elastic I don't recall what exactly prompted me to open this one. 😅 IIRC the two visualizations show the same information because the filter is the same. I expect the Unfortunately, I don't have an environment with Google Workspace data to show an example for reference right now. |
From this page: https://support.google.com/a/answer/7102416?hl=en Given that we don't have a company wide definition of what a "Compromised User" is, we could change the visualization title to "Suspicious Logins" or "Logins that are Suspicious" and add the filter for the is_suspicious flag |
I think that's reasonable. A login being flagged as suspicious doesn't mean it's compromised. |
further investigation uncovered another type of login event which is a device login event. There is a flag called is_compromised on device logins. So this MAY show a successful login on a device that is compromised |
Date | 2025-01-30T15:14:20-05:00 |
For the
login
data stream. the[Logs Google Workspace] Login
dashboard (source) contains two panels using the same filters:Total Successful Login [Logs Google Workspace]
Successful Logins by Compromised Users [Logs Google Workspace]
Filter:
data_stream.dataset: "google_workspace.login" AND "event_action: "login_success"
The
Compromised Users
panel shows all successful logins and is missing additional filters to limit only to compromised accounts.The text was updated successfully, but these errors were encountered: