Пікірлер
@surya9900k
@surya9900k 15 сағат бұрын
SecurityAlert Logs are not getting pulled up
@trinity6880
@trinity6880 14 күн бұрын
thank you very much man!! :D
@dongodilorica6037
@dongodilorica6037 15 күн бұрын
Nice work. Thanks senpai.
@gliceriojrlajara4329
@gliceriojrlajara4329 25 күн бұрын
Could ypu make new syslog/cef firwarder lab seiries with the new sentinel ama connector?
@jwild1979
@jwild1979 Ай бұрын
Why containers not VMs? Total noob here. I went from picking up a few WI. Fi smart bulbs to deciding Hey and at home. Automation would be better than the cloud apps. 2, Hey, I need to build myself a home lab computer to run. Home assistant, and now i'm here and I don't know how I got here and yeah
@AmadouMANE-rt4rz
@AmadouMANE-rt4rz Ай бұрын
create alerts, use look up file, long query also is good
@mr.sevent.7557
@mr.sevent.7557 Ай бұрын
I honestly see this video being helpful with repetition. Thanks 🙏🏿
@infosec4391
@infosec4391 Ай бұрын
Yes, really good stuff, but the isnotnull doesn't work for strings. isnotempty works better for the description.
@olafhoogstad446
@olafhoogstad446 3 ай бұрын
Good morning :) A BIG thank you from me for explaining KQL so well and in an easy to understand way! You ae a KQL life saver for me :)
@benb8291
@benb8291 3 ай бұрын
man this is way better than all the udemy courses lol awesome job bro
@2223ams
@2223ams 3 ай бұрын
Thanks a lot for this. I'm a non-tech person retraining on a network+ prep course that's insanely fast-paced and not particularly well organized. Thankfully, the instructor included your video as part of the workbook and it actually made sense to me. I appreciate you man.
@simple-security
@simple-security 4 ай бұрын
great video but it's now obsolete. consider a new on on the AMA agent.
@timdryer
@timdryer 4 ай бұрын
When 900 years old you reach, code this good you will not!!
@rahmanmahmoodi8573
@rahmanmahmoodi8573 5 ай бұрын
What book is this please?
@fingerw
@fingerw 6 ай бұрын
This was a good video - I can always used a cheat sheet.
@zakecysec
@zakecysec 6 ай бұрын
my rsyslog.conf not same like you, did i need to update it manual or what i must to make it easier ?
@zakecysec
@zakecysec 6 ай бұрын
tail: cannot open 'messages' for reading: No such file or directory help
@LegoDinoMan
@LegoDinoMan 6 ай бұрын
Wow, that's incredible. Thank you for sharing!
@simple-security
@simple-security 6 ай бұрын
any updates on your BI > Sentinel dashboards?
@TheTerminator317
@TheTerminator317 6 ай бұрын
I am little confused with arg_max function still. From what I understood was arg_max will return maximum value for whatever column is in the bracket. For example let's say I have following simple query. This will return single row as result of latest value as we're passing TimeGenerated in brackets to arg_max SecurityEvent | where TimeGenerated > ago(1d) | summarize arg_max(TimeGenerated, *) But when I replace this with following query, it gives me multiple results. SecurityEvent | where TimeGenerated > ago(1d) | summarize arg_max(TimeGenerated, AccountType, Activity) by Account So this is kinda confusing me as it's not giving just maximum value but multiple results. Is it because of what you explained at around @ 16.21 in this video?? So far I am finding your tutorials helpful in understanding KQL better as this is something that has always challenged me within Azure..
@RahulSingh-r6t
@RahulSingh-r6t 6 ай бұрын
What is the headset you are using? 🙂
@happysigmass
@happysigmass 7 ай бұрын
Today my school had gotten hacked and it was because these kids were going on bad websites and the firewall got open and hackers were able to get into all our computers and find our information. But it’s was only in middle school so elementary kids were fine. They did change the password though which I don’t know if that did anything tbh
@navisionator2854
@navisionator2854 7 ай бұрын
A great tutorial. Many thanks for it 😃
@jonathonstufflebeam7433
@jonathonstufflebeam7433 7 ай бұрын
My jam
@zaki-x6r
@zaki-x6r 8 ай бұрын
Why i don't have message file in /var/log ?
@yusareba
@yusareba 8 ай бұрын
Can this be done for free? I'm interesting in doing this but assume it has costs associated
@rajeshravichandran2170
@rajeshravichandran2170 8 ай бұрын
Thanks brother for this KQL tutorial videos. It is helpful
@taofeekadisa7619
@taofeekadisa7619 8 ай бұрын
How can I automate this process with power automate or any other tool?
@allwayshype
@allwayshype 8 ай бұрын
Thank you so much for doing this series! It’s helped me SO much!
@riadoszh6616
@riadoszh6616 8 ай бұрын
nice video! it was very useful and very interesting :) your content is very informative. thank you for your valuable contribution! please keep going!
@sergiocarmona7238
@sergiocarmona7238 9 ай бұрын
one question can you make subqueries in KQL and join?
@TeachJing
@TeachJing 9 ай бұрын
Yes a couple ways to achieve. One example is to embed the subquery in parenthesis when you join it. Just need a common reference common between both tables
@GetFitStayFit1
@GetFitStayFit1 9 ай бұрын
How would I import the samples into the powerbi or load up the samples as you're showing. Can you do a video on that process
@ericmyrs
@ericmyrs 9 ай бұрын
This is pretty cool but that's not how groups in regex works. 0 is the whole match but without regex syntax, 1 is the first group, 2 is the second etc. if you do match "thing (one) (two)" then 0 returns " thing one two", 1 returns one, and 2 returns two.
@xaviercortez5625
@xaviercortez5625 10 ай бұрын
I subscribed because of the animation. Will be watching from the beginning of the playlists. Good stuff to capture attention.
@jimtaylor4938
@jimtaylor4938 10 ай бұрын
What about the AMA agent ?
@darrensmith5544
@darrensmith5544 10 ай бұрын
Good vid!
@rmp5s
@rmp5s 11 ай бұрын
Great vid, my dude. Would love to see an updated video with the new AMA agent. OMS is going away. For some reason.
@sdrawkcab8911
@sdrawkcab8911 11 ай бұрын
Great video, also just wanted to let you know that I was sent here by one of your interns. 😂
@atul2651
@atul2651 11 ай бұрын
Thanks for the video, quick query: Is there anyway to join more than 2 tables ?
@nsomba
@nsomba Жыл бұрын
Hello @Teachjing, All your tutorials are very helpful I know my question might be two years late but the "protectionstatus" table no longer seems to have no sample data work with . I am trying to work with your instructions but the "protectionstatus" table within the database "security and audit " has no sample data so what would you suggest we use as an alternative ?
@Compy-m4g
@Compy-m4g Жыл бұрын
Studying for my SC-200 as of current! This has come in so much help, I think I am primarily struggling with the tables and filters, and just understanding the processes, any tips to simplify this or how to learn this any quicker from a non-technical background.
@TeachJing
@TeachJing Жыл бұрын
Just imagine water. When you filter the water, the output of that water can be filtered again. This can be chained as many times as you want to get to the output you desire. Water -> remove sand -> remove bacteria -> add bleach -> boil it -> desired water state. In KQL the output of a result can be filtered again by adding another pipe “|”. You can pipe as many times as you want which doesn’t look very nice but still gets the job done 😀 Table | filter by certain time | filter by certain hostname | summarize by event count | desired output One key note to know is you can’t unfilter what you have filtered just like water, but you can move the sequence around. An example is you typically want to summarize at the end. If you do it in the beginning, you may not have the desired result you want.
@willmclean8743
@willmclean8743 Жыл бұрын
@@TeachJinghighly appreciate this! Thank you so much for the series and the information!
@trendyniro
@trendyniro Жыл бұрын
Thank you so much Teachjing! you gave me loads of info!...
@GiscardYoryor-x1d
@GiscardYoryor-x1d Жыл бұрын
Hi Sir. Thanks for you great work. I have learned a lot from your videos. However, there is one thing I can’t seem to figure out. I want to run a query where the data is found in 2 different tables (SecurityAlert & SigninLogs). The common column in both tables is “UsedId”. How can I use join or union operator to put these 2 tables together and get my data. The common column in the 2 tables is “UsedId” SecurityAlert | where AlertName == "Unfamiliar sign-in properties" | where AlertSeverity == "High" SigninLogs | where RiskState == "atRisk"
@TeachJing
@TeachJing Жыл бұрын
I made a video on joins ! That will solve your scenario and you would reference that common tables
@Sharlie909
@Sharlie909 Жыл бұрын
Nice vid!!! 🦾
@Burco20007
@Burco20007 Жыл бұрын
Regarding the difficulty level, I must say that it was just right for me. The material was presented in a way that was challenging enough to keep me engaged but also manageable to grasp. I'm glad to hear that it will get better as the series progresses, and I'm excited to continue learning. Once again, thank you for your dedication to teaching and your willingness to assist learners. I truly appreciate the support and look forward to continuing this journey with your valuable guidance. Once again, thank you for your dedication to teaching and your willingness to assist learners. I truly appreciate the support and look forward to continuing this journey with your valuable guidance.