Azure Sentinel Log Screen KQL mode to start by default

Jan Stodola 56 Reputation points
2024-07-10T11:05:41.85+00:00

Azure Sentinel changed about a month ago the Log page GUI. It added a default Simple Mode, which does not seem to allow to enter KQL query by typing. The KQL mode, much more practical, needs to be selected over and over in the right side of the screen. Is there a way to go directly to KQL mode of the Log page?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,166 questions
{count} vote

Accepted answer
  1. Cam C 90 Reputation points
    2024-07-11T12:01:16.1033333+00:00

    Just figured it out, go to the LAW window, click the three dots near where it says "Simple Mode" or "KQL Mode" and select the "Log Analytics Settings", in there you can set default mode to show KQL mode without selecting each time!

    2 people found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.