Forum Discussion
FaRa_AVM
Apr 09, 2025Copper Contributor
Log Analytics Workspace - ThreatIntelIndicators
Morning!
I have been working on migrating some of our tenant analytic rules to use the new TI ThreatIntelIndicators table.
However, I noticed the following:
When querying against the new table, I get these values in a tenant log workspace
When I do the same query in another tenant logs workspace, I get this result back
If I expand the query to grab last 7 days, I get results back
but they are wildly different from what I see from one tenant to another. I can find big and small discrepancies in the logs I see.
I still can't find the connector on the connectors page (When I filter them out by data type). I can see the one that is being used for the soon to be decommissioned table. As far as I understand, the connector is not going to be changed per se, just how we access the logs from any given log analytics workspace.
I'm expecting to see the same values across my log workspaces since it comes from the same connector, and provided by MS, or is this ingestion of TI logs tenant scope and each one has different settings? I couldn't find something that tells me this in the docs.
Or is this part of the rollout problems we are expecting to see?
Thanks!
No RepliesBe the first to reply