Forum Discussion
cybersal82
Aug 13, 2025Copper Contributor
Sentinel to Detect Storage Account Created
Hi Everyone, When trying to generate query to show storage account when they are created, I'm having bad luck of not been able to see it in Sentinel. The KQL query I have is: AzureActivity | w...
Kidd_Ip
Aug 14, 2025MVP
How about this:
AzureActivity
| where ResourceProviderValue == "Microsoft.Storage"
| where OperationNameValue has "write"
| where ActivityStatusValue == "Succeeded"
| where Properties has "storageAccounts"
| project TimeGenerated, ResourceGroup, Resource, Caller, OperationNameValue, ActivityStatusValue
- cybersal82Aug 18, 2025Copper Contributor
Thanks for reading my post. I'll definitely test it and I'll let you know.