Forum Discussion
Kusto: query for ssl cert expiry date
kusto666 Yes,
Here is the query..
Event
| where EventLog == "Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational"
| where EventID == 1003
| parse EventData with * "<SubjectName>" subject: string "<" *
| parse EventData with * "<NotValidAfter>" CertExpDate: datetime "<" *
| extend remainingday = CertExpDate - TimeGenerated
//| extend val = format_timespan(DaysLeft, 'd')
| extend DaysLeft = datetime_diff('day', CertExpDate, TimeGenerated)
//| summarize count() by subject, CertExpDate, val, RenderedDescription,Message, Computer
| where DaysLeft <= 45
| summarize max(TimeGenerated)by DaysLeft, Computer, CertExpDate, EventID,subject
//| summarize count() by subject, CertExpDate,EventID, RenderedDescription,Message, DaysLeft, Computer
//| top 20 by DaysLeft asc
//| order by DaysLeft asc