cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

L5 Sessionator

Hi @VenuK ,

 

We have a management auditing dataset which can give out the details for the same. Also, this is something for Cortex XDR management audit logs can be sent over emails as notifications for the same.

 

You can use Cortex XDR sample XQL to review data and filter as per your choice:

dataset = management_auditing
| filter (management_auditing_type in (MANAGEMENT_AUDIT_EXTENSIONS_POLICY_RULES, MANAGEMENT_AUDIT_POLICY_PROFILES, MANAGEMENT_AUDIT_PREVENTION_POLICY_RULES, MANAGEMENT_AUDIT_XDR_COLLECTORS_POLICY, MANAGEMENT_AUDIT_EXTENSIONS_PROFILES))

 

 

Hope this helps!

 

Regards,

Who rated this post