The InteractiveSessions collector gathers information about live interactive sessions on managed devices.
Collector output
Field
Type
Description
userid
String
The user name that is logged into the session.
name
String
The user's full name.
Note
This field is not reported for non-local users.
Example: Show interactive sessions for user 'owilde'
InteractiveSessions where InteractiveSessions userid equals "owilde"
Note
On Windows devices, information of past sessions may appear in the results if they belonged to accounts from different domains that have the same userid as the currently active one.
Endpoint Detection and Response with Forensics (EDRF) > Investigate potential threats with EDRF > Conduct searches > Search real-time data of endpoints for investigation and threat hunting > Collecting device data for real-time search > Built-in collectors