elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
193 stars 415 forks source link

[google_workspace] Missing extra filters for `Successful Logins by Compromised Users` panel #8745

Open ebeahan opened 8 months ago

ebeahan commented 8 months ago

For the login data stream. the [Logs Google Workspace] Login dashboard (source) contains two panels using the same filters:

Filter: data_stream.dataset: "google_workspace.login" AND "event_action: "login_success"

The Compromised Users panel shows all successful logins and is missing additional filters to limit only to compromised accounts.

elasticmachine commented 8 months ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)