Log Analytics Query - Azure Active Directory ExtendedProperties
I'm currently working on a query in Log Analytics which requires me to filter on properties which are in the ExtendedProperties field. See below example, I would like to use the ExtendedProperties.Value property in my query.
Can someone point me to some tips on how to expand and filter on this value?
RE: Log Analytics Query - Azure Active Directory ExtendedProperties
Hi, You should be able to do | extend properties =
parse_json(tostring(ExtendedProperties) ) | where
tostring(properties.Name) == "XYZ" You might not be required to cast
Name into string but it doesn't matter. Dan