blueteam
Blue Team cyberhakon 1 year ago 100%

geo_info_from_ip_address() - Azure Data Explorer

learn.microsoft.com

If we are going to build a good community, we need some content! Here's a new feature in Kusto I have found useful in Sentinel, making it easier to do geolocation lookups in queries: geo_in_from_ip_address.

If we all share a little trick or something we have recently learned now and then, this will be a useful community!

5
0
Comments 0