Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security analyst is investigating a suspicious login activity incident in Microsoft Sentinel. The analyst needs to quickly identify all other activities performed by the same user account across different data sources within a specific timeframe. Which Kusto Query Language (KQL) operator is best suited for this task?

  1. Asearch
  2. Bjoin
  3. Csummarize
  4. Dunion
Show answer & explanation

Correct answer: D. union

The 'union' operator in KQL is used to combine results from multiple tables into a single result set, which is ideal for correlating activities of a single entity (like a user) across different log sources.

Why the other options are wrong

  • A. 'search' is a free-text search operator and less precise for structured correlation across different tables.
  • B. 'join' combines rows from two tables based on matching values in specified columns, but 'union' is more straightforward for simply stacking results from different sources.
  • C. 'summarize' aggregates data within a single table, not combines across multiple tables.

KQL 'union' operator

The 'union' operator in Kusto Query Language (KQL) combines the result sets of two or more queries into a single result set, stacking rows from different tables.

  • Combines rows from multiple tables.
  • Useful for correlating data across different log sources.
  • Requires compatible column names or explicit mapping.

Memory trick: To 'unite' different activity logs, use 'union' for a complete picture.

More Mitigate threats using Microsoft Sentinel questions