Forum Discussion
LeenoldTN
Feb 18, 2023Copper Contributor
KQL: Closing an incident if the events do not include entries in a Watchlist
Good day all. I want to automatically close an incident if the events do not include entries in a watchlist. I have another playbook that looks at entities and matches them with the entries...
gcorsini
Feb 18, 2023Copper Contributor
Your pseudocode is a little hard to follow without the full context of what you’re trying to accomplish. Would you mind sharing the actual query, and the original query you’re basing it off of? Obviously obfuscate anything that would be deemed proprietary to your organization (such as the watchlist itself) but I think have both queries would help us determine the source of your errors.
Thanks in advance!
Thanks in advance!