Forum Discussion

deepak198486's avatar
deepak198486
Copper Contributor
Mar 21, 2023

howto find number of events contributing to incidents in last one month in sentinel.

how to find number of events contributing to incidents in last one month in sentinel.
  • Clive_Watson's avatar
    Clive_Watson
    Mar 21, 2023

    deepak198486 

    Thats screen shot helped.

     

    SecurityIncident
    | where TimeGenerated > ago(30d)
    | summarize arg_max(TimeGenerated,*) by tostring(IncidentNumber), Severity
    | extend Alerts = extract("\\[(.*?)\\]", 1, tostring(AlertIds))
    | mv-expand AlertIds to typeof(string)
    | join 
    (
        SecurityAlert
        | extend Search_Query_Results_Overall_Count_ = tostring(parse_json(ExtendedProperties).["Search Query Results Overall Count"])
        | summarize AlertCount=dcount(SystemAlertId) by SystemAlertId, Search_Query_Results_Overall_Count_
    ) on $left.AlertIds == $right.SystemAlertId
    | project IncidentNumber, AlertCount, Search_Query_Results_Overall_Count_

Resources