Hello everyone. I have been trying to set up a lab on my Azure Sentinel tenant to receive sysmon logs. I have followed some of the tutorials posted using the agents. Everything seem to work fine
I am receiving logs from sysmon to azure, but where I am having problems is with the Sysmon Workbook.
I get the error below, and nothing is being rendered. Has anyone run into this before?
'project' operator: Failed to resolve table or column expression named 'process_create_whitelist'
If issue persists, please open a support ticket. Request id: