How to execute KQL queries in Sentinel Notebooks?

Brass Contributor

Hi. I have installed kqlmagic library and trying to connect to my log analytics workspace to execute the kql queries in Notebooks. Can anyone help me the different approaches on how to connect to the specific workspace and execute kql queries in Notebooks?


I'm aware of this below approach on connecting to the specific workspace and executing kql queries, but I'm looking for another way?


%kql loganalytics://tenant=TENANT_ID;clientid=CLIENT_ID;clientsecret=APP_ID;workspace=WORKSPACE_ID;alias='azsecdb'


2 Replies

@printscreen This Azure Sentinel notebook gives a few ways "A Getting Started Guide For Azure Sentinel ML Notebooks".   This is definitely a good notebook to go through as it gives you an overview of what the notebooks can do.


There is a PowerShell version of this as well, A Getting Started Guide for Azure Sentinel notebooks with PowerShell,  if you prefer to use PowerShell instead of Python.  It does not use the kqlmagic library but rather makes PowerShell calls to get the Azure Sentinel information 

To be able to run a KQL query in a Microsoft Sentinel notebook you need to install the MSTICPy or KQLMagic library and use a %kql magic command at the start of a query.