Hi @Khoa Tran , yes this is possible. Here's an example query:
SigninLogs
| where TimeGenerated >= ago(24h) // Set the time period here (e.g., 24h for the last 24 hours)
| extend Country = LocationDetails.countryOrRegion, IPAddress = IPAddress
| where Country != "YourCountry" // Replace "YourCountry" with the country you want to exclude
| summarize count() by Country, IPAddress
| sort by count_ desc
This query retrieves sign-in logs from the last 24 hours, extracts the country and IP address, filters out sign-ins from a specific country, and then groups and counts the sign-ins by country and IP address. You can adjust the time period by changing the value in the ago()
function. Remember to replace "YourCountry" with the country you want to exclude from the results.
Please let me know if you have any questions and I can help you further.
If this answer helps you please mark "Accept Answer" so other users can reference it.
Thank you,
James