Microsoft Sentinel Analytic Rules
Detect instances of multiple client errors occurring within a brief period of time ASIM Web Session

RulenameDetect instances of multiple client errors occurring within a brief period of time (ASIM Web Session)
DescriptionThis detection mechanism identifies situations where multiple client errors originate from a single source within a limited time frame.
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Uri Session Essentials/Analytic Rules/MultipleClientErrorsWithinShortTime.yaml
Arm templatefaa40333-1e8b-40cc-a003-51ae41fa886f.json
// HTTP response status codes indicate whether a specific HTTP request has been successfully completed.
// Please refer this for more details:
let threshold = 100; // You can set threshold value that suits your environment
| where toint(EventResultDetails) between (400 .. 499)
| summarize
    TotalErrorCount = count(),
    EventStartTime = min(TimeGenerated),
    EventEndTime = max(TimeGenerated),
    URLs=make_set(Url, 100),
    by SrcIpAddr, bin(TimeGenerated, 5m), SrcUsername, SrcHostname
| where TotalErrorCount > threshold
| extend Name = iif(SrcUsername contains "@", tostring(split(SrcUsername,'@',0)[0]),SrcUsername), UPNSuffix = iif(SrcUsername contains "@",tostring(split(SrcUsername,'@',1)[0]),""), Threshold=threshold
- T1190
- T1133
- T1071
