I was trying to hunt for a specific behavior with EQL sequences and I have a question.
If events have the same exact timestamp EQL won't work.
Here is an example EQL Query :
sequence by winlog.event_data.TargetUserName with maxspan=10s [iam where event.action: "added-computer-account"] [iam where event.action: "reset-password"] [iam where event.action: "changed-computer-account"] [iam where event.action: "enabled-user-account"]
It doesn't give me any correlated events :
but in the discover panel i can see that it should be hence my question :
Can I look for sequences with events generated in any order ?