A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
How to resolve the error 'union' operator: Failed to resolve table expression named 'Okta_CL'
I think the underlying issue is that the Okta_CL table in this environment is not populated due to the new okta connection being used which populates OktaV2_CL.
I am using this out of the box Analytics rule Okta Fast Pass Phishing Detection pasted below:
I am not understanding how a Union is being used in this logic, and again I think the real issue is that the product has not been updating Analytics rules that are deployed in the content hub>data connectors.
This is not the first time I've run into this issue with the Okta_CL table, which again is not populated and the OktaV2_CL table is.
OktaSSO
| where eventType_s == 'user.authentication.auth_via_mfa'
| where outcome_result_s == 'FAILURE'
| where outcome_reason_s == 'FastPass declined phishing attempt'
| summarize StartTime = min(TimeGenerated), EndTime = max(TimeGenerated) by actor_alternateId_s, actor_displayName_s, client_userAgent_os_s, client_ipAddress_s, client_geographicalContext_state_s,displayMessage_s, outcome_result_s,
outcome_reason_s, column_ifexists('debugContext_debugData_logOnlySecurityData_s', ""), debugContext_debugData_threatSuspected_s, client_userAgent_rawUserAgent_s,client_userAgent_browser_s, severity_s, client_geographicalContext_city_s, client_geographicalContext_country_s
| extend Location = strcat(client_geographicalContext_city_s, "-", client_geographicalContext_country_s)