Yet Another Security Blog

Another blog to help expand Security Knowledge

  • Home
  • Disclaimer
  • LinkedIn
  • Twitter
  • Email

Month: June 2020

Nice shortcut in KQL to get JSON data in a dynamic column.

Posted on June 7, 2020

While looking at the SigninLogs table in Azure Sentinel I noticed there are a lot of dynamic fields that hold JSON data. I was trying to use parse_json to get to the data but it was always returning empty fields. I then realized that parse_json requires a string input, not a dynamic. After some messing […]

Continue Reading
Posted in Azure, KQL, Programming, Queries, SentinelLeave a Comment on Nice shortcut in KQL to get JSON data in a dynamic column.

Recent Posts

  • Using PowerShell with Microsoft Graph
  • Microsoft Sentinel REST APIs vs MS Graph
  • Introduction to DevSecOps
  • Create multiple rules from rule templates using a UI
  • Changing directions

Archives

  • January 2025
  • November 2024
  • February 2024
  • December 2023
  • November 2023
  • October 2023
  • July 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • May 2021
  • February 2021
  • January 2021
  • November 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020

Categories

  • Azure
  • Hunting
  • KQL
  • Programming
  • Queries
  • Reports
  • Sentinel
  • Uncategorized
WordPress Theme: BlogGem by TwoPoints.