Sentinel
-
In this blog I will be going through a tool which you can use to turn the analytic rules which exist into your environment into a ARM template which you can then deploy. (Please note this only currently supports scheduled analytic rules). This means, if you have an analytic rule which exists only in your…
-
In this post I go through Kusto Query Language – A very powerful querying tool used by Azure Data Explorer and Log Analytics Workspace’s. Why I learnt KQL I learnt KQL because I work at a company which uses Microsoft Sentinel, a powerful SIEM tool, which is actually built of an Azure log analytics workspace…