Forum Discussion

FaRa_AVM's avatar
FaRa_AVM
Copper Contributor
Apr 09, 2025

Log Analytics Workspace - ThreatIntelIndicators

Morning! 
I have been working on migrating some of our tenant analytic rules to use the new TI ThreatIntelIndicators table. 

However, I noticed the following:

When querying against the new table, I get these values in a tenant log workspace

 

 

When I do the same query in another tenant logs workspace, I get this result back

 

 

If I expand the query to grab last 7 days, I get results back

 

but they are wildly different from what I see from one tenant to another. I can find big and small discrepancies in the logs I see. 

I still can't find the connector on the connectors page (When I filter them out by data type). I can see the one that is being used for the soon to be decommissioned table. As far as I understand, the connector is not going to be changed per se, just how we access the logs from any given log analytics workspace. 

I'm expecting to see the same values across my log workspaces since it comes from the same connector, and provided by MS, or is this ingestion of TI logs tenant scope and each one has different settings? I couldn't find something that tells me this in the docs. 

Or is this part of the rollout problems we are expecting to see?

Thanks!

 

No RepliesBe the first to reply

Resources