Watchlist use force query time in log analytics

User989846-7900 1 Reputation point
2022-01-20T14:29:44.893+00:00

Hello,

Have I missed something with watchlist use? Time is set by default when using a watchlist, even for non existing watchlist:
166828-image.png

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
982 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Alistair Ross 7,101 Reputation points Microsoft Employee
    2022-01-20T16:17:45.087+00:00

    Hello

    _GetWatchlist() is function within the Sentinel Workspace, which you can see in the image below, has a time range filter. If you are using Analytics rules, hunting queries and workbooks, your time range will be scoped to the period of time selected. For raw logs, I would recommend that you implement a time range in your query, as the watchlist code time range is auto detected and will return all data in your workspace.

    166873-image.png

    0 comments No comments