Forum Discussion

staro69's avatar
staro69
Copper Contributor
Jun 17, 2021

Filtering using watchlist on multiple fields

Hello,   I am new to KQL. I am trying to use watchlists to filter out some false positives from a rule in sentinel. I can do the filtering based on one field from watchlist, but what if I need comb...

Resources