Freigeben über


Abfragen für die UrlClickEvents-Tabelle

Böswillige Links, durch die der Benutzer fortfahren durfte.

UrlClickEvents
| where ActionType == "ClickAllowed" or IsClickedThrough !="0"
| where ThreatTypes has "Phish"
| summarize by ReportId, IsClickedThrough, AccountUpn, NetworkMessageId, ThreatTypes, Timestamp