Forum Discussion

mikhailf's avatar
mikhailf
Steel Contributor
Apr 27, 2023
Solved

TI map in several tables

Hello Tech Community, 

 

We are trying to map TI indicators in several tables in Sentinel. 

It is clear how to take 1 type of indicator (IP, for example) and look for it in 1 table (firewalls, for example).

 

But what if we want to build only 1 KQL for it and we want to look for this indicator in firewalls, switches, mail relay, etc.  

 

We've tried to play with union/joins, but without success. The only message we received was about exessive amount of resources required to perform the query 😄

 

Has anyone here built something like this? What are the pros and cons of such a query?

 

1 Reply

Resources