Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A security analyst is building a custom workbook in Microsoft Sentinel to visualize the top 10 most frequently accessed IP addresses by external entities over the last 24 hours. The analyst needs to count the occurrences of each IP address and then display only the top 10. Which Kusto Query Language (KQL) operators should the analyst combine to achieve this in the most efficient way?
- Asort by and limit
- Bproject and take
- Csummarize by and top
- Ddistinct and count
Show answer & explanationAnswer & explanation
Correct answer: C. summarize by and top
To count occurrences and then get the top N, the 'summarize by' operator is used to group and count the IP addresses, and then the 'top' operator is used to efficiently retrieve the specified number of top results based on that count.
Why the other options are wrong
- A. 'sort by' and 'limit' would work but are generally less efficient than 'top' when you specifically need the top N, as 'sort by' sorts the entire dataset first.
- B. 'project' selects columns, and 'take' (or 'limit') selects a number of arbitrary rows, not the top N based on a calculated value.
- D. 'distinct' gets unique values, and 'count' gets the total number of records, but they don't directly provide a count per unique value or the top N.
KQL 'summarize' and 'top' operators
The 'summarize' operator groups rows by specified columns and performs aggregations, while the 'top' operator efficiently returns the first N rows sorted by specified columns.
- 'summarize' is for aggregation (e.g., count(), sum()).
- 'top' is optimized for retrieving the top N records.
- Often used together for 'top N by count' scenarios.
Memory trick: Summarize, then Top: Count and Crown!