Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard

A security operations team uses Azure Monitor to collect diagnostic logs from Azure Key Vault. They need to create an alert that triggers specifically when a 'SecretGet' operation fails due to insufficient permissions. This alert should contain details about the caller, the Key Vault name, and the specific secret involved. Which Kusto Query Language (KQL) operator is most effective for extracting specific fields from a log entry and then filtering based on custom criteria?

  1. Aproject
  2. Bjoin
  3. Csummarize
  4. Dparse
Show answer & explanation

Correct answer: A. project

The 'project' operator in KQL is used to select specific columns, rename them, or add new calculated columns to the output. This is essential for extracting relevant fields like caller, Key Vault name, and secret from the diagnostic log entry after filtering for failed 'SecretGet' operations, ensuring the alert contains the necessary details.

Why the other options are wrong

  • B. The 'join' operator combines rows from two tables, which is not needed for extracting fields from a single log entry.
  • C. The 'summarize' operator aggregates data, which is not the primary goal of extracting specific fields for an alert.
  • D. The 'parse' operator extracts structured data from unstructured text fields, but 'project' is used to select and shape the columns once the data is already parsed or structured.

KQL 'project' operator

The Kusto Query Language (KQL) 'project' operator selects the columns to include in the output, renames columns, or adds new computed columns. It is fundamental for shaping query results to display only the relevant information needed for analysis or alerting.

  • Selects specific columns from a table.
  • Can rename columns.
  • Can add new computed columns.
  • Essential for tailoring output for alerts or reports.

Memory trick: To project the right details, filter and shape your KQL.

More Manage security operations questions