Forum Discussion
roadruner
Oct 29, 2020Copper Contributor
Watchlist and query
new to kql here, is it possible to build a query that search's across logs looking for machines that connected to any of ip addresses in the watchlist? Any examples ? Plan would be to turn that que...
- Oct 30, 2020
roadruner This is the starting query for something like that.
let ClearedIPAddresses=_GetWatchlist('test1');
CommonSecurityLog
| join ClearedIPAddresses on $left.SourceIP== $right.IPAddress
GaryBushey
Oct 30, 2020Bronze Contributor
roadruner This is the starting query for something like that.
let ClearedIPAddresses=_GetWatchlist('test1');
CommonSecurityLog
| join ClearedIPAddresses on $left.SourceIP== $right.IPAddress
roadruner
Oct 30, 2020Copper Contributor
GaryBushey Thanks! This worked. Just replaced sourceip to destip. and .found the test hits to the list. either way works.