Forum Discussion

ankit976's avatar
ankit976
Copper Contributor
Dec 28, 2021

Usecase if IDS/IPS turned off on firewall ( In azure sentinel ) @Azure

Want to create one use case  if IDS/IPS turned off on firewall ( In azure sentinel ). Can any one help with Kusto query for this. 
  • Clive_Watson's avatar
    Jan 05, 2022
    You don't mention which Firewall. Azure Firewall, logs IPS/IDS so you can start a query with AzureDiagnostics | where ResourceType == "AZUREFIREWALLS" | where OperationName == "AzureFirewallIDSLog"

Resources