What is the most effective KQL query for looking at sign-in activity trying to access a Storage Account from a specific IP address?

maybe this guide could help?

How to query Azure Storage logs in Azure Monitor Log Analytics | Azure Tips and Tricks - YouTube


| where AppDisplayName == "Azure Storage"
| where IPAddress == "x.x.x.x" // Replace 'x.x.x.x' with the specific IP address you want to filter for
| project TimeGenerated, UserPrincipalName, AppDisplayName, IPAddress, Status, LocationDetails


