Skip to contentBrand Logo
Community
Help
Learn
Events
Cyber Million
  1. Immersive Community
  2. Help
  3. Help & Support Forum

Forum Discussion

itskw271's avatar
itskw271
Icon for Bronze I rankBronze I
5 months ago

Sentinel Blue team ops

2 separate questions for KQL can someone lmk what I'm doing wrong please.

 

 

cloud security
defensive cyber

1 Reply

  • Cyb3rM0nK3y's avatar
    Cyb3rM0nK3y
    Icon for Bronze II rankBronze II
    5 months ago

    Q12 - I can see 2 issues with your query.

    • On line 2 the "2" needs to be outside the () but within [] of its own. 
    • You don't need line 4

     

    Q11 - You have the time range set to "Last 24 Hours" the lab requires you to have it set to "Last 7 Days"

    Hope that helps 🙂

Featured Places

Help & Support Forum

Related Content
  • Sentinel Labs
    7 months ago
    FF
  • Microsoft Sentinel SOAR: Demonstrate Your Skills
    4 months ago
    Cyb3rM0nK3y
  • Microsoft Sentinel SOAR: Playbooks Issue
    5 months ago
    Cyb3rM0nK3y
  • Hasta La Vista, Passive Defense: Why Blue Teams Need an Offensive Edge
    13 days ago
    EllaBendrickChartier
  • How is Cyber Team Sim different from Cyber Ranges?
    9 months ago
    KieranRowley

Recent Discussions

  • IronLady18's avatar
    Fundamental AI Algorithms: Decision Trees Script Detection Question 6
    15 hours ago
    IronLady18
  • clermagic224's avatar
    Active Directory Basics: Demonstrate Your Skills
    Solved
    24 hours ago
    clermagic224
  • CyberSharpe's avatar
    Introduction to Detection Engineering: Ep.3 – Parent Processes - Kibana says no
    Solved
    2 days ago
    CyberSharpe
  • PRABAKARANRAMAMURTHY's avatar
    PowerShell Deobfuscation: Ep.8 - Stuck Halfway
    2 days ago
    PRABAKARANRAMAMURTHY
  • QuickSloth's avatar
    Stuck on "SQL Injection (Module 1) : File download"
    Solved
    2 days ago
    QuickSloth
Community HomePrivacy PolicyHelp
Powered By Khoros