FF
21 days agoBronze II
Sentinel Labs
My team and I have been encountering a few peculiar issues with the Microsoft Azure Sentinel based labs (KQL, Sentinel Blue Team Ops, Sentinel SOAR, etc.) where correct answers do not appear to be ge...
Hi Matt,
Thanks for the response - yep we've ruled that out, mostly we've found that the methodology is the same, but the results will vary.
In these instances, we've had results of fairly simple queries that don't seem to match up to the answer in the lab, sometimes off-by-1, sometimes exactly half/double the expected number, and in other instances we've got absolutely no idea what the correct answer could be. For a lot of the harder questions, I'd usually pass this off as user error and tell them to keep trying, but we've had issues on questions as simple as using Summarize to count the number of results of a what I'd consider to be a simple query.
I'll touch base with the team and see if any of them can give me specific/evidenced instances of this happening.
Cheers!
James
Interesting! Thanks for the info, James.
If you let me know the specific labs I will make sure the team look into it and revert back here when I know more :)
Matt