Blog Post

Microsoft Sentinel Blog
4 MIN READ

Azure Sentinel correlation rules: Active Lists out; make_list() in, the AAD/AWS correlation example

Ofer_Shezaf's avatar
Ofer_Shezaf
Icon for Microsoft rankMicrosoft
Nov 25, 2019
  Writing alert rules using KQL is powerful but does not have to be complex. A good example would be rules which in traditional SIEM use Active Lists (or Reference Sets, depending on your SIEM). Wh...
Updated Dec 29, 2020
Version 12.0