Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A security analyst is investigating a suspicious login activity incident in Microsoft Sentinel. The analyst needs to quickly identify all other activities performed by the same user account across different data sources within a specific timeframe. Which Kusto Query Language (KQL) operator is best suited for this task?
- Asearch
- Bjoin
- Csummarize
- Dunion
Show answer & explanationAnswer & explanation
Correct answer: D. union
The 'union' operator in KQL is used to combine results from multiple tables into a single result set, which is ideal for correlating activities of a single entity (like a user) across different log sources.
Why the other options are wrong
- A. 'search' is a free-text search operator and less precise for structured correlation across different tables.
- B. 'join' combines rows from two tables based on matching values in specified columns, but 'union' is more straightforward for simply stacking results from different sources.
- C. 'summarize' aggregates data within a single table, not combines across multiple tables.
KQL 'union' operator
The 'union' operator in Kusto Query Language (KQL) combines the result sets of two or more queries into a single result set, stacking rows from different tables.
- Combines rows from multiple tables.
- Useful for correlating data across different log sources.
- Requires compatible column names or explicit mapping.
Memory trick: To 'unite' different activity logs, use 'union' for a complete picture.