Forum Discussion

ThreatHunter2289's avatar
ThreatHunter2289
Copper Contributor
Nov 15, 2021

Looking for Correct Syntax for below Kql Query with multiple and or conditions

Trying to generate alert where more than 10 txt request has been sent in 5 min or where bas64 encoded data has been sent in txt or AAAA record of DNS   | where (count_ >= 10 and TimeSpan <= timespa...