Forum Discussion

andrew_bryant's avatar
andrew_bryant
Brass Contributor
Jul 02, 2020

Query MD ATP schema from Sentinel analytics rule

Is it possible to write a query in Sentinel analytics that can access the schema in our MD ATP workspace without bringing those logs into our Sentinel workspace (which would get very expensive)?