Azure Log Analytics: Queries, the basics explained - Part 4

added by Paul Wheeler
12/19/2017 1:11:41 PM

1 Kicks, 251 Views

I'll finish with some more examples, building on what we discussed in part 3. SecurityEvent | where Account has "Clive" // has is a best practise rather than contains | project Account, Computer, EventID , EventSourceName // now I've selected a few columns of data I think are useful to reduce the noise //or...