Forum Discussion

Pranesh1060's avatar
Pranesh1060
Copper Contributor
Nov 05, 2019

Querying Azure Sentinel Logs Using KQL

Hello,

 

We have integrated MCAS with Azure Sentinel using the data connector available. All the logs are being sent to Sentinel and so far it is good. To dig deeper and understand the logs by using KQL, I was looking for a few use case examples that would help us. Any documentation or links that you people can direct me to?

I came across this article and it is good!! Looking for a few more examples like this. Apart from this any other documentation that would help to help understand Sentinel better?

https://techcommunity.microsoft.com/t5/Azure-Sentinel/Tip-Easily-use-JSON-fields-in-Sentinel/ba-p/768747

4 Replies

Resources