Figured out the problem.
I removed the \ escapes from the directories on the Watchlist.
So now the Watchlist entries look like \directory01\conf\fileA.ini
Results are now filtered as expected.
Sentinel KQL | Use contains with a Watchlist
carmike
6
Reputation points
Is it possible to use contains on a Watchlist?
Like:
let DataOfInterest = (_GetWatchlist('DataWatchlist')| project SearchKey);
| where FieldOfInterest contains (DataOfInterest )
2 answers
Sort by: Most helpful
-
carmike 6 Reputation points
2022-08-01T19:53:14.593+00:00 -
Clive Watson 5,711 Reputation points MVP
2022-08-01T10:05:43.41+00:00 You can use "in" instead?
let DataOfInterest = _GetWatchlist("ComputerList") | project SearchKey; Heartbeat | where Computer in (DataOfInterest ) | summarize count() by Computer