Queries for the ProtectionStatus table

Signatures out of date

Devices with Signatures out of date.

// To create an alert for this query, click '+ New alert rule'
| summarize Rank = max(ProtectionStatusRank) by Computer, _ResourceId
| where Rank == "250"

Protection Status updates

Protection Status updates per day.

// To create an alert for this query, click '+ New alert rule'
| summarize AggregatedValue = count(ScanDate) by bin(TimeGenerated, 1d), Computer, _ResourceId
| sort by TimeGenerated desc

Malware detection

Malware detected grouped by threat.

// To create an alert for this query, click '+ New alert rule'
| where ThreatStatus != "No threats detected" 
| summarize AggregatedValue = count() by Threat, Computer, _ResourceId