Add an extra filter:
| where datetime_part("hour", TimeGenerated) between (9 .. 18)
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello,
I'm working on a playbook to report on zero events from CAPAMAuditLog.The query below looks in the CAPAMAuditLog table and provides the count of events for the last 2 hours excluding Saturday and Sunday.
I also want to include only office hours(9am-6pm) in the query. How can I best achieve this?
Thank you!
let Saturday = time(6.00:00:00);
let Sunday = time(0.00:00:00);
CAPAMAuditLog
| where TimeGenerated > ago(2h)
| where dayofweek(TimeGenerated) != Saturday
| where dayofweek(TimeGenerated) != Sunday
| count
Add an extra filter:
| where datetime_part("hour", TimeGenerated) between (9 .. 18)