@mikhailf , making the output the same schema will make it easier to use
the same queries across both. I've made a simple PowerShell function for
this exact scenario to duplicate tables from an existing one found here.
The-Cloud-Brain-Dump/Toolshed/Sentinel
Toolbox/Copy-LogAnalyticsTable.ps1 at main...
@Erik_Snijder for data value optimizations - yes! If your custom logs
aren't used for detections, or not used at all, it'll be surfaced in a
recommendation.
Grate article. Thank you. If we want to split logs from Syslog table to
another Custom-Table1. Should the Custom-Table1 have the same schema as
Syslog?Is it possible to split logs from Syslog to 2 or more tables?
Latest Comments