Forum Discussion
JeremyTBradshaw
Aug 28, 2024Iron Contributor
How to KQL query *live* EmailEvents table and NOT the streaming API
EmailEvents table in the advanced hunting schema - Microsoft Defender XDR | Microsoft Learn - this page tells us: Note * The LatestDeliveryLocation and LatestDeliveryAction columns are not availabl...
- Aug 30, 2024
I tried Bing Chat today to see if it might help me. It has already seen and uses this very post to confirm my theory as fact (i.e., time range in query = streaming API / time range set via selector dropdown in UI = live table). I guess me and Copilot are taking the cake on this one. It's now "documented" as truth :).
JeremyTBradshaw
Aug 30, 2024Iron Contributor
I tried Bing Chat today to see if it might help me. It has already seen and uses this very post to confirm my theory as fact (i.e., time range in query = streaming API / time range set via selector dropdown in UI = live table). I guess me and Copilot are taking the cake on this one. It's now "documented" as truth :).