Jun 26 2021 03:21 PM
here is the query below. I would like to be able to determine which specific business unit server an alert was generated into Azure sentinel but I am unable to create a tag that includes a watchlist that provides the expected result. Please help
Heartbeat
| lookup kind=leftouter _GetWatchlist('MBSFQDN_01')
on $left.Computer == $right.SearchKey
| project UNIT, Computer
Jul 06 2021 08:09 AM