Search queries should be included in Enterprise Events API
6
votes

Thank you for your submission. However, this does not have enough demand in order to be prioritized.
We will reconsider with additional use cases.
-
Murakami Akihiko @ Marubeni IT Solutions commented
I also strongly do support this request.
When a malicious user tries to steal confidential information without being noticed by SIEM, he/she searches for some specific keyword to reach to the target document.
We need to detect those suspecious user who searches for those word.