Forum Discussion

Alexander_Ceyran's avatar
Alexander_Ceyran
Copper Contributor
Apr 06, 2020

Retrieve "dismiss alert" logs in Sentinel

Hello everyone :smile:,

 

I hope you all doing well, I'm trying to retrieve the dismiss alerts logs for MCAS in Azure Sentinel using Azure Log Analytics, however I don't have the raw data as usual which doesn't enable me to know the log type. Are these activities retrievable by any chance (using KQL, API) ?

 

Thank you,

Stay safe.

 

Alexander

Resources