Explore all file activity by user and event action
Target Huntset
google_workspace
Target hunt Type
ES|QL
Query
from logs-google_workspace*
| where file.name == "*" or file.name is not null and event.action
| stats files=count(*) by file.name, user.email, event.action
| sort files asc
Description
Explore all file activity by user and event action
Target Huntset
google_workspace
Target hunt Type
ES|QL
Query
Related issues or PRs
4121
References
No response
Redacted Example Data
No response