Home

Querying Azure Sentinel Logs Using KQL

%3CLINGO-SUB%20id%3D%22lingo-sub-982750%22%20slang%3D%22en-US%22%3EQuerying%20Azure%20Sentinel%20Logs%20Using%20KQL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-982750%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20integrated%20MCAS%20with%20Azure%20Sentinel%20using%20the%20data%20connector%20available.%20All%20the%20logs%20are%20being%20sent%20to%20Sentinel%20and%20so%20far%20it%20is%20good.%20To%20dig%20deeper%20and%20understand%20the%20logs%20by%20using%20KQL%2C%20I%20was%20looking%20for%20a%20few%20use%20case%20examples%20that%20would%20help%20us.%20Any%20documentation%20or%20links%20that%20you%20people%20can%20direct%20me%20to%3F%3C%2FP%3E%3CP%3EI%20came%20across%20this%20article%20and%20it%20is%20good!!%20Looking%20for%20a%20few%20more%20examples%20like%20this.%20Apart%20from%20this%20any%20other%20documentation%20that%20would%20help%20to%20help%20understand%20Sentinel%20better%3F%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FTip-Easily-use-JSON-fields-in-Sentinel%2Fba-p%2F768747%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FTip-Easily-use-JSON-fields-in-Sentinel%2Fba-p%2F768747%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-990205%22%20slang%3D%22en-US%22%3ERe%3A%20Querying%20Azure%20Sentinel%20Logs%20Using%20KQL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-990205%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F428046%22%20target%3D%22_blank%22%3E%40Pranesh1060%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHave%20you%20looked%20at%20the%20Workbook%20for%20MCAS%20and%20its%20queries%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20716px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F155471iBF5AF136AE8215EB%2Fimage-dimensions%2F716x467%3Fv%3D1.0%22%20width%3D%22716%22%20height%3D%22467%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-992121%22%20slang%3D%22en-US%22%3ERe%3A%20Querying%20Azure%20Sentinel%20Logs%20Using%20KQL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-992121%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239477%22%20target%3D%22_blank%22%3E%40Clive%20Watson%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20Clive!!%20It%20helps!!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20this%20is%20not%20what%20exactly%20I%20am%20looking%20for.%20Let%20me%20give%20you%20an%20example%20for%20this%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20want%20to%20be%20able%20to%20write%20queries%20to%20deep%20dive%20into%20the%20logs%20we%20get%2C%20parse%20the%20json%20parameters%20that%20we%20have%20and%20use%20the%20columns%20after%20parsing%20into%20an%20alert%20for%20Logic%20Apps.%20I%20was%20looking%20for%20documentations%20like%20the%20one%20I%20shared%20in%20the%20post%20to%20be%20able%20to%20make%20more%20sense%20out%20of%20the%20logs.%20Is%20it%20doable%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-994911%22%20slang%3D%22en-US%22%3ERe%3A%20Querying%20Azure%20Sentinel%20Logs%20Using%20KQL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-994911%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F428046%22%20target%3D%22_blank%22%3E%40Pranesh1060%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EUnderstood.%26nbsp%3B%20There%20are%20many%20many%20logs%20and%20many%20ways%20of%20looking%20at%20them.%26nbsp%3B%20There%20are%20quite%20a%20few%20examples%20but%20you%20do%20need%20experience%20with%20KQL%2C%20have%20you%20done%20the%20free%20course%3F%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.pluralsight.com%2Fcourses%2Fkusto-query-language-kql-from-scratch%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.pluralsight.com%2Fcourses%2Fkusto-query-language-kql-from-scratch%3C%2FA%3E%26nbsp%3Byou%20can%20also%20view%20the%20course%20contents%20in%20the%20demo%20portal%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fms.portal.azure.com%2F%23blade%2FMicrosoft_Azure_Monitoring_Logs%2FDemoLogsBlade%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fms.portal.azure.com%2F%23blade%2FMicrosoft_Azure_Monitoring_Logs%2FDemoLogsBlade%3C%2FA%3E%26nbsp%3B%20(you%20can%20see%20the%20Pluralsight%20material%20form%20here%20as%20well)%3B%20open%20the%20Query%20Explorer%20and%20look%20in%20the%20folder%20marked.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F155827iF1E6B235FBD05A5E%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1006931%22%20slang%3D%22en-US%22%3ERe%3A%20Querying%20Azure%20Sentinel%20Logs%20Using%20KQL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1006931%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F428046%22%20target%3D%22_blank%22%3E%40Pranesh1060%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22line-height%3A%2012.0pt%3B%20background%3A%20%23FFFFFE%3B%22%3E%3CSPAN%20style%3D%22font-size%3A%2010.5pt%3B%20font-family%3A%20Consolas%3B%20color%3A%20black%3B%22%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2Fparseoperator%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2Fparseoperator%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22line-height%3A%2012.0pt%3B%20background%3A%20%23FFFFFE%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22line-height%3A%2012.0pt%3B%20background%3A%20%23FFFFFE%3B%22%3E%3CSPAN%20style%3D%22font-size%3A%2010.5pt%3B%20font-family%3A%20Consolas%3B%20color%3A%20black%3B%22%3EThis%20might%20be%20worth%20the%20look.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Pranesh1060
Occasional Contributor

Hello,

 

We have integrated MCAS with Azure Sentinel using the data connector available. All the logs are being sent to Sentinel and so far it is good. To dig deeper and understand the logs by using KQL, I was looking for a few use case examples that would help us. Any documentation or links that you people can direct me to?

I came across this article and it is good!! Looking for a few more examples like this. Apart from this any other documentation that would help to help understand Sentinel better?

https://techcommunity.microsoft.com/t5/Azure-Sentinel/Tip-Easily-use-JSON-fields-in-Sentinel/ba-p/76...

4 Replies

@Pranesh1060 

 

Have you looked at the Workbook for MCAS and its queries?  

 

clipboard_image_0.png

@Clive Watson 

 

Thanks Clive!! It helps!!

 

But this is not what exactly I am looking for. Let me give you an example for this

 

I want to be able to write queries to deep dive into the logs we get, parse the json parameters that we have and use the columns after parsing into an alert for Logic Apps. I was looking for documentations like the one I shared in the post to be able to make more sense out of the logs. Is it doable?

@Pranesh1060 

 

Understood.  There are many many logs and many ways of looking at them.  There are quite a few examples but you do need experience with KQL, have you done the free course? https://www.pluralsight.com/courses/kusto-query-language-kql-from-scratch you can also view the course contents in the demo portal https://ms.portal.azure.com/#blade/Microsoft_Azure_Monitoring_Logs/DemoLogsBlade  (you can see the Pluralsight material form here as well); open the Query Explorer and look in the folder marked.

clipboard_image_0.png

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
30 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies