Forum Discussion
Aman_Khan
Jul 25, 2022Copper Contributor
Sentinel Alert- Querying multiple Entities
Hi team, Trying to build an alert in Sentinel when a phish report is submitted by users, an email containing sender,recipient and subject in sent to ops team. Query I have built in my logic app ...
- Jul 26, 2022Take a look at the mv-expand operator and see if that will work for you. https://docs.microsoft.com/en-us/azure/data-explorer/kusto/query/mvexpandoperator
GaryBushey
Jul 26, 2022Bronze Contributor
Take a look at the mv-expand operator and see if that will work for you. https://docs.microsoft.com/en-us/azure/data-explorer/kusto/query/mvexpandoperator