Appendix A
Introduction to Kusto Query Language
BY MIKE KASSIS,SENIOR PROGRAM MANAGERMICROSOFT CxE SECURITY
The Kusto Query Language, referred to as KQL in this book, is the language you will use to work with and manipulate your data consumed by Microsoft Sentinel. The logs you feed into your workspace aren’t worth much if you can’t visualize and analyze the important data therein. The best part of KQL is that the power and flexibility of the language is matched by its simplicity. If you have a background in scripting or working with databases, much of what I cover here will feel very familiar. If not, don’t worry, you will walk away from this appendix ready to start writing your own queries and driving value for your organization.
This appendix ...
Get Microsoft Sentinel: Planning and implementing Microsoft's cloud-native SIEM solution, 2nd Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.