Forum Discussion
roadruner
Oct 29, 2020Copper Contributor
Watchlist and query
new to kql here, is it possible to build a query that search's across logs looking for machines that connected to any of ip addresses in the watchlist? Any examples ? Plan would be to turn that que...
- Oct 30, 2020
roadruner This is the starting query for something like that.
let ClearedIPAddresses=_GetWatchlist('test1');
CommonSecurityLog
| join ClearedIPAddresses on $left.SourceIP== $right.IPAddress
GaryBushey
Oct 30, 2020Bronze Contributor
roadruner Here is a simple example of how to do this. I created a CSV file that has all the IPAddresses I have cleared and uploaded that into the Watchlist using "ClearedIPAddreses" as the alias.
let ClearedIPAddresses=_GetWatchlist('ClearedIPAddresses');
Heartbeat
| join ClearedIPAddresses on $left.ComputerIP == $right.IPAddress
catilintouchadmin
Jul 01, 2021Copper Contributor