NRT New access credential added to Application or Service Principal

M Nurohmat 100 Reputation points
2023-07-04T03:56:14.3+00:00

NRT queries cannot use joins or unions, or query more than one table.

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Accepted answer
  1. Clive Watson 7,866 Reputation points MVP Volunteer Moderator
    2023-07-05T15:54:01.0233333+00:00

    That is correct, please see here for more: https://learn.microsoft.com/en-us/azure/sentinel/near-real-time-rules#considerations

    Do you have a question about this?


1 additional answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator
    2023-07-05T19:39:51.58+00:00

    @M Nurohmat

    Thank you for your post!

    Error Message:
    NRT queries cannot use joins or unions, or query more than one table

    I understand that you're trying to leverage the near-real-time (NRT) analytics rules but when creating the rule you're running into the above error. To hopefully point you in the right direction or resolve your issue I'll share my findings below.


    Findings:

    Because Near-real-time (NRT) rules are currently in PREVIEW, please keep in mind that there are still limitations currently governing the use of NRT rules.

    User's image

    Because you can create NRT rules the same way you create regular scheduled-query analytics rules - When it comes to your template deployment, you should be able to identify if it's an NRT rule or a scheduled query rule through the Query scheduling and alert threshold. For more info.

    • Unlike regular scheduled rules that run on a built-in five-minute delay to account for ingestion time lag, NRT rules run on just a two-minute delay.

    I hope this helps!

    If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.