Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
991 questions
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi,
When Sentinel Custom analytics query is built do we need to mention the time generated filter in query.
E.g:
If am writing a Custom analytics to Run query every 1 hour and look for data for last 1 hour do i still send to mention Time generated > ago(1h) in query ? i saw couple of gallery content with and without this Timegerated option
AuditLogs
| where Timegenerated > ago(1h)