turbot/tailpipe-mod-gcp-audit-log-detections

Query: Top 10 Actors

Usage

powerpipe query gcp_audit_log_detections.query.activity_dashboard_logs_by_actor

Tailpipe Tables

SQL

select
authentication_info.principal_email as "Actor",
count(*) as "Logs"
from
gcp_audit_log
where
authentication_info.principal_email is not null
group by
authentication_info.principal_email
order by
count(*) desc
limit 10;

Dashboards

The query is used in the dashboards: