Forum Discussion
JMSHW0420
Feb 10, 2023Iron Contributor
RE: Tracking Security Incidents linked to an Intune device
Hello,
I already have a similar request asking about this but wanted to change the scoping of the query being asked.
Is it possible with KQL to 'track' ANY Security Incidents (primarily generated from an Analytics Rule) that are associated or linked to an 'Intune' Device?
I know the 'SecurityIncident' table can locate the 'Incidents' but which table(s) can I perform a JOIN on to find those Incidents associated with an 'Intune' Device?