Transform the vast amount of raw data from Azure Data Explorer, Azure Monitor, Microsoft Sentinel, and other Microsoft data platforms into actionable insights using KQL (Kusto Query Language). Information security and analytics experts guide you on how to automate your approach to risk assessment and mitigation, accelerating detection time while reducing manual work using KQL. This accessible and practical guide—designed for a wide range of people with different experience in KQL—will quickly make KQL second nature for information security.
Solve real-world problems with the Kusto Query Language—and build your competitive advantage:
- Learn the fundamentals of KQL—what it is and where it is used.
- Examine the anatomy of a KQL Chapter.
- Understand why cumulative processing and data aggregation are important.
- See examples of cumulative data processing, including count, countif, and dcount.
- Learn the benefits of transitioning from raw data import to a more automated approach for security businesses.
- Discover how to write efficient and effective queries.
- Work with advanced KQL operators, advanced data, and multiple strings.
- Explore KQL for everyday administrative tasks, performance, and troubleshooting.
- Use KQL across Azure, including app services and operational apps.
- Dive into defense and threat hunting using KQL.
- Recognize signs of related harm and anomaly detection.
- Learn to access and contribute to search queries via GitHub and toolkits via Microsoft Entra ID.
Pages: 480, Dimensions: 36x36cm
Manufacturer
- Publisher
- Pearson
- Type
- Anatomy
- Language
- English
- Subtitle
- -
- Cover
- Soft
- Number of Pages
- -
- Release Date
- -
- Publication Date
- 2024
- Dimensions
- -
- ISBN-13
- 9780138293383
Important information
Specifications are collected from official manufacturer websites. Please verify the specifications before proceeding with your final purchase. If you notice any problem you can report it here.