KQL
KQL
SecurityEvent
SecurityEvent
Level == 9,"High",
Level == 8,"High",
Level == 7,"Medium",
Level == 6,"Medium",
Level == 5,"Medium",
Level == 4,"Low",
Level == 3,"Low",
Level == 2,"Low",
Level == 1,"Low",
"Informational")
| limit 50
Order by
SecurityEvent
Level == 9,"High",
Level == 8,"High",
Level == 7,"Medium",
Level == 6,"Medium",
Level == 5,"Medium",
Level == 4,"Low",
Level == 3,"Low",
Level == 2,"Low",
Level == 1,"Low",
"Informational")
| limit 50
Project
Exclude the column , include the column , rearrange and rename the column
SecurityEvent
Level == 8,"High",
Level == 7, "HIgh",
Level == 6, "Medium",
Level == 5, "Medium",
Level == 4, "Low",
Level == 3, "Low",
Level == 2, "Low",
Level == 1,"Low",
"Information"
| project-reorder Hostname,Sevirity,CommandLine,Account
| project-keep Hostname,Sevirity,CommandLine,Account
| limit 50
Summarise
SecurityEvent
Level == 8, "High",
Level == 4, "Medium",
"Informational")
|limit 50
SecurityEvent
| where TimeGenerated > ago(7d) and EventID == "4688" and Process == "WmiPrvSE.exe"
Level == 4, "Medium",
"Informational")
|limit 50
Dcount
SecurityEvent
| limit 50
SecurityEvent
|project-reorder Hostname,Account,Level,TimeGenerated,Activity
|project-keep Hostname,Account,Level,TimeGenerated,Activity
| limit 50
Make_set
SecurityEvent
| limit 50
Render
SecurityEvent
| limit 50
| render piechart
Render
Perf
|render columnchart
Bin
SecurityEvent
|render timechart
@"\administrator",
@"NT AUTHORITY\SYSTEM",
@"NA\SQL10$"
];
SecurityEvent