Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
982 questions
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello,
Have I missed something with watchlist use? Time is set by default when using a watchlist, even for non existing watchlist:
Hello
_GetWatchlist() is function within the Sentinel Workspace, which you can see in the image below, has a time range filter. If you are using Analytics rules, hunting queries and workbooks, your time range will be scoped to the period of time selected. For raw logs, I would recommend that you implement a time range in your query, as the watchlist code time range is auto detected and will return all data in your workspace.