Forum Discussion

Paul MacKinnon's avatar
Paul MacKinnon
Copper Contributor
Jan 31, 2018
Solved

How to use "inverted commas" within search query

Hi, I am trying to create a search query for when a Public IP is assigned to a NIC, and then create an alert off that. I can find the part which identifies the assignment, but I need to use "inverted...
  • Evgeny Ternovsky's avatar
    Feb 01, 2018

    Hi,

     

    Please check out info on strings in KQL here. Since it looks like all your quotes are " and not 's, you can encompass your search terms in ' ... 's, and then use "s within that search unescaped. Backslashes can be escaped via \\. 

     

    If that doesn't work, can you please provide a sample (anonymized) of the properties field of one of these entries? I can try and put the right search expression together based on that.

     

    Thanks,
    -Evgeny

Resources