Useful resources for working with Kusto Query Language in Microsoft Sentinel
Microsoft Sentinel uses Azure Monitor's Log Analytics environment and the Kusto Query Language (KQL) to build the queries that undergird much of Sentinel's functionality, from analytics rules to workbooks to hunting. This article lists resources that can help you skill up in working with Kusto Query Language, which will give you more tools to work with Microsoft Sentinel, whether as a security engineer or analyst.
Microsoft technical resources
Microsoft Sentinel documentation
Azure Monitor documentation
Reference guides
Microsoft Sentinel Learn modules
- Write your first query with Kusto Query Language
- Learning path SC-200: Create queries for Microsoft Sentinel using Kusto Query Language (KQL)
Other resources
Microsoft TechCommunity blogs
- Advanced KQL Framework Workbook - Empowering you to become KQL-savvy (includes webinar)
- Using KQL functions to speed up analysis in Azure Sentinel (advanced level)
- Ofer Shezaf's blog series on correlation rules using KQL operators:
Training and skilling resources
- Rod Trent's Must Learn KQL series
- Pluralsight training: Kusto Query Language from Scratch
- Log Analytics demo environment