Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelEasy

A security analyst needs to create a custom workbook in Microsoft Sentinel to display specific security metrics and trends for executive reporting. The workbook requires data from both Azure Activity logs and Microsoft Entra ID audit logs. Which language is primarily used to query and visualize this data within a Sentinel workbook?

  1. AKQL (Kusto Query Language)
  2. BSQL (Structured Query Language)
  3. CPython
  4. DPowerShell
Show answer & explanation

Correct answer: A. KQL (Kusto Query Language)

Kusto Query Language (KQL) is the primary query language used across Azure Monitor, Log Analytics, and therefore Microsoft Sentinel, for querying and visualizing data in workbooks, analytics rules, and hunting queries.

Why the other options are wrong

  • B. SQL is a relational database query language and is not directly used for querying data within Log Analytics or Sentinel workbooks.
  • C. Python can be used for automation or external scripting with Sentinel APIs, but not for direct data querying within workbooks.
  • D. PowerShell is a scripting language for automation and management, not for querying security logs within Sentinel workbooks.

Kusto Query Language (KQL)

A powerful, read-only query language used to explore, analyze, and visualize data in Azure Data Explorer and Azure Monitor Log Analytics, including Microsoft Sentinel.

  • Used for analytics rules, hunting queries, workbooks, and interactive log searches.
  • Designed for large datasets and time-series analysis.
  • Features rich operators for filtering, aggregation, and joining data.

Memory trick: KQL is the 'universal translator' for all your Sentinel data questions.

More Mitigate threats using Microsoft Sentinel questions