แก้ไข

แชร์ผ่าน


Useful resources for working with Kusto Query Language in Microsoft Sentinel

Microsoft Sentinel uses Azure Monitor's Log Analytics environment and the Kusto Query Language (KQL) to build the queries that undergird much of its functionality, from analytics rules to workbooks to hunting. This article lists resources that can help you skill-up in working with Kusto Query Language, giving you more tools to work with Microsoft Sentinel, whether as a security engineer or analyst.

Microsoft technical resources

Microsoft Sentinel documentation

Kusto documentation

Reference guides

Microsoft Sentinel Learn modules

Other resources

Microsoft TechCommunity blogs

Training and skilling resources

Next steps