Forum Discussion
'where' operator: Failed to resolve table or column expression named 'SecurityEvent'
- Sep 02, 2018
I posted a video with a walkthrough on log collection setup. The quick version is to go into the Log Analytics workspace in Azure, Go to Workspace Overview and Add. Scroll down to the Security and Compliance solution.
You could also try going into Logs (Preview) for Advanced Log Analytics and check what shows in the Schema.
http://www.ciraltos.com/azure-oms-step-by-step-log-collection-setup/
Sorry about that. My site is hosted in the Azure South Central region and that seems to be offline this morning. Here is a link to the video in YouTube. https://www.youtube.com/watch?v=OI2iUIh340U&list=PLnWpsLZNgHzVXXyN9a0jm9xNNDrikHf8I&index=3&t=0s
Hi Travis,
Fantastic video .. very informative. Thanks
Unfortunately, the video doesn't cover adding Security Policy to allow the the following query from being added with the error:
'where' operator: Failed to resolve table or column expression named 'SecurityEvent'.
SecurityEvent
| where TimeGenerated > ago(30m)
| count