'where' operator: Failed to resolve table or column expression named 'SecurityEvent'

%3CLINGO-SUB%20id%3D%22lingo-sub-241731%22%20slang%3D%22en-US%22%3E'where'%20operator%3A%20Failed%20to%20resolve%20table%20or%20column%20expression%20named%20'SecurityEvent'%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-241731%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20Community%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20originally%20submitted%20this%20question%20here%20asking%20for%20help%20with%20this%20matter.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Log-Analytics%2Fwhere-operator-Failed-to-resolve-table-or-column-expression%2Ftd-p%2F241234%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Log-Analytics%2Fwhere-operator-Failed-to-resolve-table-or-column-expression%2Ftd-p%2F241234%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20chap%20called%20Travis%20mentioned%20I%20could%20find%20the%20answer%20from%20the%20following%20link%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22http%3A%2F%2Fwww.ciraltos.com%2Fazure-oms-step-by-step-log-collection-setup%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Fwww.ciraltos.com%2Fazure-oms-step-by-step-log-collection-setup%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20the%20link%20appears%20to%20be%20broken.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETravis%2C%20if%20you%20pick%20this%20up%2C%20you're%20help%20will%20be%20greatly%20appreciated%20in%20providing%20an%20alternative%20link%20to%20your%20video%20solution.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOtherwise%2C%20any%20help%20resolving%20this%20issue%20will%20be%20greatly%20appreciated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECarlton%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-241731%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-242023%22%20slang%3D%22en-US%22%3ERe%3A%20'where'%20operator%3A%20Failed%20to%20resolve%20table%20or%20column%20expression%20named%20'SecurityEvent'%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-242023%22%20slang%3D%22en-US%22%3EIn%20case%20Travis%20does%20not%20answer%20here%20is%20some%20guidance.%20The%20Security%20%26amp%3B%20Audit%20solution%20is%20no%20longer%20standalone%20solution.%20It%20is%20part%20of%20Azure%20Security%20Center%20(ASC).%20To%20use%20ASC%20and%20that%20solution%20you%20need%20to%20be%20on%20the%20Standard%20SKU%20for%20ASC.%20The%20doc%20for%20upgrading%20to%20Standard%20tier%20is%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-onboarding%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-onboarding%3C%2FA%3E%20You%20will%20also%20need%20to%20upgrade%20the%20SKU%20of%20the%20Log%20Analytics%20workspace%20as%20well.%20Informaiton%20on%20the%20same%20link.%20Additionally%20to%20the%20same%20workspace%20you%20will%20deploy%20the%20Security%20%26amp%3B%20Audit%20solution%20from%20the%20marketplace%3A%20%3CA%20href%3D%22https%3A%2F%2Fazuremarketplace.microsoft.com%2Fen-au%2Fmarketplace%2Fapps%2FMicrosoft.SecurityOMS%3Ftab%3DOverview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fazuremarketplace.microsoft.com%2Fen-au%2Fmarketplace%2Fapps%2FMicrosoft.SecurityOMS%3Ftab%3DOverview%3C%2FA%3E%20Below%20blog%20post%20will%20also%20help%20you%20understand%20how%20to%20setup%20the%20event%20logging%20level%20for%20secrutiy%20events%3A%20%3CA%20href%3D%22https%3A%2F%2Fcloudadministrator.net%2F2018%2F01%2F16%2Ftips-and-tricks-of-setting-up-azure-security-center%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fcloudadministrator.net%2F2018%2F01%2F16%2Ftips-and-tricks-of-setting-up-azure-security-center%2F%3C%2FA%3E%20More%20documentation%20on%20setting%20up%20and%20what%20events%20are%20gathered%20with%20the%20different%20levels%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-enable-data-collection%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-enable-data-collection%3C%2FA%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello Community,

 

I originally submitted this question here asking for help with this matter.

 

https://techcommunity.microsoft.com/t5/Azure-Log-Analytics/where-operator-Failed-to-resolve-table-or...

 

I chap called Travis mentioned I could find the answer from the following link:

 

http://www.ciraltos.com/azure-oms-step-by-step-log-collection-setup/

 

However, the link appears to be broken.

 

Travis, if you pick this up, you're help will be greatly appreciated in providing an alternative link to your video solution.

 

Otherwise, any help resolving this issue will be greatly appreciated.

 

Cheers

 

Carlton

1 Reply
In case Travis does not answer here is some guidance. The Security & Audit solution is no longer standalone solution. It is part of Azure Security Center (ASC). To use ASC and that solution you need to be on the Standard SKU for ASC. The doc for upgrading to Standard tier is here: https://docs.microsoft.com/en-us/azure/security-center/security-center-onboarding You will also need to upgrade the SKU of the Log Analytics workspace as well. Informaiton on the same link. Additionally to the same workspace you will deploy the Security & Audit solution from the marketplace: https://azuremarketplace.microsoft.com/en-au/marketplace/apps/Microsoft.SecurityOMS?tab=Overview Below blog post will also help you understand how to setup the event logging level for secrutiy events: https://cloudadministrator.net/2018/01/16/tips-and-tricks-of-setting-up-azure-security-center/ More documentation on setting up and what events are gathered with the different levels: https://docs.microsoft.com/en-us/azure/security-center/security-center-enable-data-collection