The Definitive Guide to KQL: Using Kusto Query Language for operations, defending, and threat hunting
by Mark Morowczynski, Rod Trent, Matthew Zorich
Foreword
Data is ubiquitous—generated by and flowing between applications, devices, users, and systems. It can provide valuable insights into the performance, behavior, and security of one’s environment. However, accessing, analyzing, and acting on this data can be challenging. How can you turn it into actionable intelligence that can help optimize operations, enhance security, and solve problems?
One solution is KQL—Kusto Query Language—a powerful and expressive language that enables the querying and manipulation of large volumes of data in Azure Data Explorer, Azure Monitor, Azure Sentinel, and other Microsoft data platforms. KQL can help perform complex queries, apply advanced functions, and leverage operators to transform data into meaningful ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access