Query
Endpoint login activity across corporate devices2
LogScale · Infrastructure · v1 · @sebastian · 2.8.2026
This query shows endpoint login events collected from corporate Windows laptops throughout the day. The log data includes device identifiers, hardware information, usernames, and login timestamps, providing visibility into user authentication activity across the managed workstation fleet. You can also exclude additional usernames. This query is based on the Falcon Data Replicator repository.
AuthenticationEndpointInvestigation
Query contentv1
Download v1Loading editor…
Version history
By default each save creates a new version. Overwrites update the current version in place. Open any version to view or download it.