ByteRay CQL Hub
← All queries

User Logon Activity

Table of all user logons.

CQL · Falcon Next-Gen SIEMCopy query
#event_simpleName=UserLogon
| groupBy([UserName, name, aid, aip, ComputerName, event_platform, LocalIP, LogonDomain, LogonServer, LogonType], function=[count(@timestamp), selectLast([@timestamp])])
| table([@timestamp, UserName, ComputerName, aid, aip, event_platform, LocalIP, LogonDomain, LogonType], limit=20000)
user_logon_activity.yml
T1078
ByteRay GmbH
Monitoring
Endpoint
Insight
2025-08-26
2025-08-26

Get this query running in your SIEM, with someone on call.

Our Managed SIEM team operates CrowdStrike Falcon Next-Gen SIEM in production, with over 350 battle-tested use cases and 24/7 incident response behind them.

Talk to the SIEM team