Sentinel Analytics Query Time Generated filter

Karthick G 101 Reputation points
2022-07-29T06:47:45.77+00:00

Hi,

When Sentinel Custom analytics query is built do we need to mention the time generated filter in query.

E.g:

If am writing a Custom analytics to Run query every 1 hour and look for data for last 1 hour do i still send to mention Time generated > ago(1h) in query ? i saw couple of gallery content with and without this Timegerated option

AuditLogs
| where Timegenerated > ago(1h)

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
991 questions
0 comments No comments
{count} votes

0 additional answers

Sort by: Most helpful