Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelEasy
A security analyst needs to create a custom detection rule in Microsoft Sentinel that identifies when a user account logs in from more than 10 distinct IP addresses within a 24-hour period. The rule should trigger an incident and include the user principal name (UPN) and the list of distinct IP addresses in the incident details. Which Kusto Query Language (KQL) operator is most critical for counting unique IP addresses in this scenario?
- Ajoin
- Bsummarize sum()
- Cdistinct
- Dcountif
Show answer & explanationAnswer & explanation
Correct answer: C. distinct
The 'distinct' operator, often used with 'summarize', is essential for counting unique values in a column, such as distinct IP addresses, which is precisely what the scenario requires.
Why the other options are wrong
- A. join combines rows from two tables based on a common column, not for counting unique values within a single table.
- B. summarize sum() calculates the total sum of a numeric column, not the count of unique values.
- D. countif counts rows that satisfy a predicate, but 'distinct' is more direct for counting unique values.
KQL distinct operator
The 'distinct' operator in KQL returns a table with the unique combinations of the provided columns. It's often used with 'summarize' to count unique items.
- Returns unique values in a column or set of columns.
- Useful for counting unique entities (e.g., users, IPs).
- Can be used as a standalone operator or within summarize functions.
Memory trick: Distinctly Count Unique IPs