New Blog Post | Must Learn KQL Part 11: The Summarize Operator

%3CLINGO-SUB%20id%3D%22lingo-sub-3052760%22%20slang%3D%22en-US%22%3ENew%20Blog%20Post%20%7C%20Must%20Learn%20KQL%20Part%2011%3A%20The%20Summarize%20Operator%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3052760%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22AshleyMartin_0-1641404819174.png%22%20style%3D%22width%3A%20681px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F337605i092B2782A60A93FA%2Fimage-dimensions%2F681x521%3Fv%3Dv2%22%20width%3D%22681%22%20height%3D%22521%22%20role%3D%22button%22%20title%3D%22AshleyMartin_0-1641404819174.png%22%20alt%3D%22AshleyMartin_0-1641404819174.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fazurecloudai.blog%2F2022%2F01%2F05%2Fmust-learn-kql-part-11-the-summarize-operator%2F%3FWT.mc_id%3Dm365-0000-rotrent%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMust%20Learn%20KQL%20Part%2011%3A%20The%20Summarize%20Operator%20%E2%80%93%20Azure%20Cloud%20%26amp%3B%20AI%20Domain%20Blog%20(azurecloudai.blog)%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EFor%20this%20part%20in%20this%20Must%20Learn%20KQL%20series%2C%20I%20once%20again%20want%20to%20take%20the%20logical%20next%20step%20as%20we%20march%20toward%20generating%20our%20very%20first%20Microsoft%20Sentinel%20Analytics%20Rule%20(see%20the%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fcda.ms%2F3yb%22%20target%3D%22_blank%22%20rel%3D%22noreferrer%20noopener%20nofollow%22%3ETOC%3C%2FA%3E%3CSPAN%3E%26nbsp%3Bfor%20the%20cadence).%20We%20have%20a%20lot%20of%20ground%20to%20cover%20before%20then%2C%20but%20the%20next%20few%20operators%20we%20talk%20about%20are%20useful%20for%20various%20reasons%20%E2%80%93%20one%20of%20those%20reasons%2C%20like%20this%20section%E2%80%99s%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fcda.ms%2F3yc%22%20target%3D%22_blank%22%20rel%3D%22noreferrer%20noopener%20nofollow%22%3E%3CEM%3ESummarize%3C%2FEM%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eoperator%3C%2FA%3E%3CSPAN%3E%26nbsp%3Btalk%2C%20is%20to%20produce%20number%20data%20to%20encapsulate%20actions.%20By%20creating%20thresholds%2C%20we%20can%20generate%20additional%20logic%20for%20how%20we%20want%20to%20react%20to%20situations.%20For%20example%2C%20if%20there%E2%80%99s%20one%20person%20that%20failed%20login%20in%20the%20last%2010%20days%2C%20it%E2%80%99s%20a%20non-issue.%20But%2C%20if%20that%20account%20failed%20login%20100%20times%20in%20the%20last%205%20minutes%20%E2%80%93%20well%20%E2%80%93%20we%20have%20a%20problem.%20Summarizing%20the%20data%20makes%20it%20more%20meaningful.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3052760%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECloud%20Security%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Defender%20for%20Cloud%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Sentinel%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

AshleyMartin_0-1641404819174.png

Must Learn KQL Part 11: The Summarize Operator – Azure Cloud & AI Domain Blog (azurecloudai.blog)

For this part in this Must Learn KQL series, I once again want to take the logical next step as we march toward generating our very first Microsoft Sentinel Analytics Rule (see the TOC for the cadence). We have a lot of ground to cover before then, but the next few operators we talk about are useful for various reasons – one of those reasons, like this section’s Summarize operator talk, is to produce number data to encapsulate actions. By creating thresholds, we can generate additional logic for how we want to react to situations. For example, if there’s one person that failed login in the last 10 days, it’s a non-issue. But, if that account failed login 100 times in the last 5 minutes – well – we have a problem. Summarizing the data makes it more meaningful.

0 Replies