Writing alert rules using KQL is powerful but does not have to be complex. A good example would be rules which in traditional SIEM use Active Lists (or Reference Sets, depending on your SIEM). Wh...
Updated Dec 29, 2020
Version 12.0Ofer_Shezaf
Microsoft
Joined March 01, 2019
Microsoft Sentinel Blog
Microsoft Sentinel is an industry-leading SIEM & AI-first platform powering agentic defense across the entire security ecosystem.