wwlpublish Work with data in Microsoft Sentinel using Kusto Query Language - Training
- Learn to use Kusto Query Language (KQL) to manipulate
string
data from log sources. You'll be able toextract
data from bothunstructured
andstructured
string fields and create functions using KQL.
‣
Introduction
‣
Extract data from unstructured string fields
‣
Extract data from structured string data
‣
Integrate external data → Reading
‣
Create parsers with functions
‣
Knowledge check
‣