wwlpublish Analyze query results using KQL - Training
- This module teaches you how to
summarize
andvisualize
data usingKQL
statements, which is essential for buildingdetections
in Microsoft Sentinel. By the end, you'll be able to effectivelysummarize
data andcreate visualizations
with KQL.
‣
Introduction
‣
Use the summarize operator
‣
Use the summarize operator to filter results
‣
Use the summarize operator to prepare data
‣
Use the render operator to create visualizations
‣
Knowledge check
‣