Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| qnd:azure:kusto_query_language_kql [2021/11/12 22:24] – mgupton | qnd:azure:kusto_query_language_kql [2022/08/25 15:46] (current) – [Kusto Query Language (KQL)] mgupton | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Kusto Query Language (KQL) ====== | ====== Kusto Query Language (KQL) ====== | ||
| * #azure #sentinel | * #azure #sentinel | ||
| + | * [[azure: | ||
| * [[https:// | * [[https:// | ||
| * [[https:// | * [[https:// | ||
| Line 23: | Line 24: | ||
| </ | </ | ||
| - | === List All Tables === | + | ==== List All Tables |
| < | < | ||
| Line 50: | Line 51: | ||
| - | === Windows Events Aggregated === | + | ==== Windows Events Aggregated |
| < | < | ||
| SecurityEvent | SecurityEvent | ||
| Line 58: | Line 59: | ||
| - | === Palo Alto firewall logs === | + | ==== Palo Alto firewall logs ==== |
| * Aggregating on ApplicationProtocol | * Aggregating on ApplicationProtocol | ||
| * Example of aggregating and sorting | * Example of aggregating and sorting | ||