Forum Discussion

sijmalik's avatar
sijmalik
Copper Contributor
Feb 22, 2021
Solved

Monitoring data connectors in Sentinel - Check if any connectors are down

Hi, You will have to forgive my basic Azure knowledge, as I'm a DBA looking after about 250 servers for various clients, but have been asked by my company if I could write some KQL that will alert t...
  • CliveWatson's avatar
    Feb 22, 2021

    sijmalik 

     

    Search and Union wildcards are not allowed (i.e union *) but you can name the Tables, as per this simple example using two common Tables:

    union SecurityAlert, SecurityEvent
    | limit 10

    (within a Analytics scheduled rule in Azure Sentinel)