Hello,
Just noticed that in the rule "Azure Excessive Signin Logs by Azure Identity" it seems impossible to display the field azure.signinlogs.identity, which is not very user friendly and a waste of time to lookup afterwards..
So 2 questions?
- Why can't we display
azure.signinlogs.identityin the signal overview? - Why is
azure.signinlogs.identitynot copied touser.namein the azure.signin pipeline?
Best regards,
Willem
