Forum Discussion
FeintBE
Feb 25, 2020Copper Contributor
Analytic rule querying
Hello, I'm working on alerting in Azure sentinel, my domain controller is connected with Azure, for example when someone trying to login to my domain, it will be logged. I already know u can ...
Rod_Trent
Microsoft
Feb 25, 2020FeintBE Are you familiar with our Livestream component in the Hunting blade. When you right-click on a query here, you can add it to the Livestream tab where you can start and stop the stream. What this does is set the query to run every 1 minute and you'll be alerted through Azure notifications as long as the livestream is active. The display for the active Livestream will also increment whenever the result is reached. This is a great way to monitor a potentially active threat.