I am new to Azure Sentinel. I am trying to run a query to check how many mailboxes received a particular email with a particular Subject, within a time period and I seem to have some trouble, will you be able to help? I am not able to run it in Microsoft search as the log I am trying to look at is more than 30 days.
From the query I ran
| where TimeGenerated > ago(360d)
| where OfficeWorkload == "Exchange"
| extend Subject_ = tostring(parse_json(AffectedItems).Subject)
| where Subject_ == "xxxxxxxxxxx"
| summarize count() by Operation
So far I can see the operation summary are all about "delete" action. I am not interested in knowing the action taken after the email has been delivered, but I am interested who received the email.
Will Sentinel able to give me that visibility?