Udemy

Learn KQL for Microsoft Sentinel

A course designed to refresh your KQL learning and help you to boost your application for Sentinel
Free tutorial
Rating: 4.5 out of 5 (226 ratings)
4,369 students
1hr 30min of on-demand video
English

Learn KQL basics for Microsoft Sentinel
Know the most used operators
Learn to build your first query
Learn to evaluate your KQL results

Requirements

  • Familiarity of KQL for Microsoft Sentinel

Description

Welcome to KQL for Microsoft Sentinel.

KQL is a simple query language used across multiple products like

Azure Log Analytics

Microsoft Sentinel

Azure Resource Graph

to read & write structured & unstructured data.

Course Structure

In this course we will focus on leveraging KQL for Microsoft Sentinel.

This will walk you though a basic understanding of KQL

  • Quick Start

  • Go for a quick result

  • Filter for better results

  • Leverage the joins

  • Summarize for perspective

  • Save & Reuse

  • Apply the visual

  • Build the use case

Each section has subsections for easy understanding of the topics.

A quick start happens with  searching a particular phrase -> projecting  the necessary columns -> extending the additional columns needed.

Now, to get a quick result we do distinct to find unique values -> use count -> get the top for display a limited set of result.

To Filter better result Apply where condition -> Apply TimeGeneated filter

Leverage the joins by learning about different kinds of joins

Summarize for perspective by Summarize -> make_list -> make_set

Once done save & reuse by saving as query or function.

Apply the visual for better visibility.

Start building you use case now with an example.

Outcome at completion

After you successfully complete this course you will be able to build your own KQL query from scratch to end.

Whom is this course for

Either you are new to Microsoft Sentinel , Log Analytics or KQL or you are already working in SOC on a regular basis, this course is for you.

Who this course is for:

  • Data Scientists

Instructor

Cloud Security Architect
  • 4.5 Instructor Rating
  • 226 Reviews
  • 4,369 Students
  • 1 Course

Currently working & evolving as a Cloud Security Advisor At Open Systems helping customers implementing

Microsoft Security Products at scale and educating them to derive the best out of it.

prima facia Microsoft Sentinel ?️ ?‍?

Been engaged in the design & development of applications in Azure, GCP.

A veteran developer for .NET & SharePoint.

Been a speaker in 20+ various community events on Cloud, Data & Security.

Enriched Microsoft Sentinel with 50+ contributions & #8 contributor in Microsoft Sentinel Community.

Author of PowerShell Module on D4IOT which was released this Ignite 2022.

Love to enrich community through GitHub

Top companies trust Udemy

Get your team access to Udemy's top 27,000+ courses