Apr 27 2023 03:20 AM
Hello Tech Community,
We are trying to map TI indicators in several tables in Sentinel.
It is clear how to take 1 type of indicator (IP, for example) and look for it in 1 table (firewalls, for example).
But what if we want to build only 1 KQL for it and we want to look for this indicator in firewalls, switches, mail relay, etc.
We've tried to play with union/joins, but without success. The only message we received was about exessive amount of resources required to perform the query :D
Has anyone here built something like this? What are the pros and cons of such a query?
Apr 27 2023 07:42 AM
SolutionApr 27 2023 07:42 AM
Solution