Forum Discussion

tijan2018's avatar
tijan2018
Copper Contributor
Feb 15, 2022

KQL

 Hi, I am trying to modify the below KQL query to use as a scheduled log analytics rule in Microsoft Sentinel to only trigger an incident when more than 10 emails have been sent on behalf of a user i...

Resources