Blog Post

Microsoft Sentinel Blog
5 MIN READ

Handling sliding windows in Azure Sentinel rules

Ofer_Shezaf's avatar
Ofer_Shezaf
Icon for Microsoft rankMicrosoft
Jul 06, 2020
In the article "Azure Sentinel correlation rules: Active Lists out; make_list() in," I presented a rule that detects several sign-in failures to Azure AD, alongside a sign-in success to AWS from the ...
Updated Dec 29, 2020
Version 2.0