Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security analyst is building a custom workbook in Microsoft Sentinel to visualize the top 10 users with the most failed login attempts over the last 24 hours. The workbook needs to display the user principal name (UPN) and the total count of failed attempts for each user. Which Kusto Query Language (KQL) operator combination is most appropriate for achieving this specific visualization requirement?

  1. Awhere ... | project ... | limit 10
  2. Bjoin ... | extend ... | top 10 by count_desc
  3. Csummarize count() by UserPrincipalName | sort by count_ desc | take 10
  4. Dsearch '*' | distinct UserPrincipalName | count
Show answer & explanation

Correct answer: C. summarize count() by UserPrincipalName | sort by count_ desc | take 10

To get the top 10 users by failed login attempts, you first need to group the failed attempts by UserPrincipalName and count them (summarize count() by...). Then, sort these counts in descending order (sort by count_ desc) and finally select the top 10 (take 10).

Why the other options are wrong

  • A. This sequence filters, projects, and limits, but doesn't aggregate (count) or sort to find the 'top 10' by a metric.
  • B. Using 'join' and 'extend' is for combining tables and adding calculated columns, not for aggregating and finding top N by count. 'top 10 by count_desc' is a valid part but needs prior aggregation.
  • D. This searches all data, finds distinct UPNs, and then counts the total distinct UPNs, not the count of failed logins per UPN.

KQL Aggregation and Top N

To find the 'top N' items based on a count or sum in KQL, you typically use the 'summarize' operator to aggregate, 'sort by' to order the results, and 'take' or 'top' to select the desired number of rows.

  • summarize: Groups and aggregates data.
  • sort by: Orders results based on specified columns.
  • take/top: Selects a specified number of rows (top or bottom N).

Memory trick: Summarize, Sort, Then Take Top

More Mitigate threats using Microsoft Sentinel questions