microsoft / AzureMonitorCommunity

An open repo for Azure Monitor queries, workbooks, alerts and more
MIT License
1.02k stars 441 forks source link

Use of watchlist to create an analytic rule in Sentinel #218

Open cybergeekwise opened 7 months ago

cybergeekwise commented 7 months ago

This rule triggers when there is a DNS query for non-local domain.

//This is my log query and watchlist

Not able to figure it out why i am not seeing the domain listed in the watchlist to my table

log_query watchlist