Jun 16 2021 12:02 PM
Is there a good source/site to translate Splunk queries into Kusto/Sentinel? I've managed to get the first part but it's the second part that is the challenge. This is what I'm looking to translate:
| stats dc(id.resp_h) as "#Dest",dc(id.resp_p) as "#Port" by id.orig_h | sort "#Dest","#Port" desc
I've tried uncoder.io but it didn't translate, just say translate temporarily unavailable.
The search is counting the unique number of destinations a source tries to access.
Thanks, Joe
Jun 16 2021 12:18 PM
Jun 17 2021 04:37 AM
Jun 21 2021 05:33 AM
@j0ebeer this specific example translate trivially. Here's a modified version for the CommonSecurityLog table:
CommonSecurityLog
| summarize ["#Src"] = dcount(SourceIP), ["#Ports"] = dcount(DestinationPort) by DestinationIP
| order by ['#Src'], ['#Ports'] desc