Oct 26 2023 01:42 AM - edited Oct 27 2023 05:43 AM
Hi Techies,
We want to use a watchlist inside a KQL query which is supposed to be simple, but we are actually struggling a bit with the following issue "'project' operator: Failed to resolve scalar expression named 'emailAddress'". According to the documentation it should look something like this, but it is not working correctly:
Our watchlist looks like this:
Sentinel Docs:
EDIT:
The problem has been solved. We have an invisible space character inside our deployment script which caused the problem. Thanks everyone for helping out, and thanks @Clive_Watson for leading us in the right direction.
Oct 26 2023 04:07 AM
Oct 26 2023 04:10 AM
Oct 26 2023 04:43 AM
Oct 26 2023 04:45 AM
Oct 26 2023 04:56 AM
SolutionOct 27 2023 05:38 AM
Oct 27 2023 05:44 AM
Oct 26 2023 04:56 AM
Solution