Sep 09 2020
As a part of our Sentinel on-boarding project, we're in the process of centralising LA workspaces.
The Sentinel LA workspace permission is set to "Use resource or workspace permissions", however the cross workspace query below fails with a permission error:
| where Computer contains "<ServerName>"
Does anyone know if the KQL can be tweaked to avoid delegating read permissions to the LA workspace? Hoping we can do something similar to user using the "logs" option from the VM.