A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Agreed. We will need more information to assist. I recommend copying the rule query into Log Analytics to run or use the test option 'runs' on the rule. When testing the query independently, try commenting out the threshold, any parameters, and possibly the project statement. Look to verify that the underlying data is present. Verify that the lookback timespan is sufficient.