Recon your Azure resources with Kusto Query Language (KQL)

Поделиться
HTML-код
  • Опубликовано: 4 дек 2024

Комментарии • 78

  • @DanaEpp
    @DanaEpp 5 лет назад +14

    I 💖 KQL. Especially in Log Analytics and Azure Resource graph. How about you? How are you using KQL?

    • @KoosGoossens
      @KoosGoossens 4 года назад

      Do you know how I could query the Azure Resource Graph with KQL from within Azure Log Analytics and/or Azure Sentinel UI?

    • @kamsanikamalakar
      @kamsanikamalakar 4 года назад

      It's helpful. I am looking for good understanding on Join or function queries in KQL. Right now i am finding difficult with them. Any suggestion?

    • @fudhater8592
      @fudhater8592 4 года назад

      KQL seems to be someone's reason for existence.

    • @vikramadithyavicky8279
      @vikramadithyavicky8279 4 года назад

      Hi, Can you suggest what tools we can use to represent these data in graphs or pie charts like in Power BI ?

  • @50PullUps
    @50PullUps 4 года назад +4

    Azure newbie here. This FREE vid cleared up the basics of the KQL better than any online training or study guide I've paid for.

  • @903koolaid91
    @903koolaid91 2 года назад +6

    I freaking love this guy!! I love the way he explains things and isn't monotoned! This helps me soo much in passing my pass two Azure certs

  • @Blackfeet
    @Blackfeet 3 месяца назад

    WOW! I've watched countless videos trying to understand KQL and this is the video that was concise enough to make sense of it all. Thank you, wodie.

  • @Shirocco7
    @Shirocco7 2 месяца назад

    Recommended video after watching an official MS course on configuring Log Analytics. Taught enough in 15min to show what the point was for this topic. Nice one.

  • @TenMinuteKQL
    @TenMinuteKQL Год назад +3

    Great session, thank you for supporting the KQL and security communities!

  • @alaingarel712
    @alaingarel712 Год назад

    Very good introduction to KQL. Very good overview in 15 minutes.

  • @k0n3j0
    @k0n3j0 2 года назад +1

    We use the same type of glasses. Thank you for the video. Cheers

  • @kevinpowers2874
    @kevinpowers2874 3 месяца назад

    I'm doing my best to learn things that are on all the job posts I'm going for and I really appreciate the way you explain KQL. Thank you good sir. I have Liked, Subscribed and well here's my comment.

  • @minstreltokunbo
    @minstreltokunbo 3 года назад

    I am screaming with joy!! I just got to know about KQL today from a video I watched on Instagram and decided to learn more. Ahhhh

  • @juanjogarcia3597
    @juanjogarcia3597 4 года назад

    Fantastic video ... I've been an SQL fan for years, you have discovered me a new way to investigate and enjoy through Azure Monitor and its Kusto QL, thank you ...

  • @codycodes
    @codycodes 4 года назад

    Great introduction! Loved the pi chart. KQL is my new go-to on Azure!

    • @KnowOps
      @KnowOps  3 года назад

      Thanks Cody. Ya, KQL is awesome.

  • @blackwasp9285
    @blackwasp9285 2 года назад

    Super vidéo 👍

  • @glitchdigger
    @glitchdigger 4 года назад +1

    Wow dude this is so great. Thanks very much for creating this video. :) Such a practical and straightforward example of both Red and Blue team capabilities here. I also really like KQL's function names and setup a lot.

    • @KnowOps
      @KnowOps  4 года назад

      Glad it was helpful! I plan to do a whole bunch of Red Team videos later this fall to help look at Azure more offensively. Stay tuned and make sure you subscribe if you haven't yet.

  • @aegan5898
    @aegan5898 2 года назад

    Great video. Thanks

  • @allanschuman7684
    @allanschuman7684 9 месяцев назад

    What type of scope for connection do you need to set to be able to see and query your working database tables? I am having a hard time figuring out how to get KQL to recognize my table names.

  • @EduAlexification
    @EduAlexification 2 года назад

    very, very useful! thank you!

  • @Corrado49
    @Corrado49 2 года назад

    very good video! Thanks!

  • @mohamedabdulmoez8902
    @mohamedabdulmoez8902 3 года назад

    Very informative!
    Thank you Dana!

  • @memyselfi7800
    @memyselfi7800 4 года назад +1

    Thanks, got a fantastic with KQL 👍

  • @jean-charles-AI
    @jean-charles-AI Год назад +1

    Nice one !

  • @Gregwilson3468
    @Gregwilson3468 3 года назад

    Excellent intro. It really helped .

  • @randytate
    @randytate 4 года назад

    Excellent presentation - both in content and execution. Well done.

  • @tiago7w_583
    @tiago7w_583 Год назад

    Vocês tem cursos de query KQL?

  • @khajareddy7222
    @khajareddy7222 3 года назад

    Thanks For Your very informative session on KQL,for next week please make an video on how to enable Log Analytics Workspace on Any Azure Resource and how to collect data in to tables

  • @adrien-barret
    @adrien-barret 2 года назад

    seems cool, how do you load a table to pickup naming ? don't see option after the | for that, like select ClusterName from KubeNodeInventory ?

  • @nandpurohit
    @nandpurohit 4 года назад

    Fantastic ! Thank you for putting this together !

  • @midhunmohan3594
    @midhunmohan3594 6 месяцев назад

    Very Interesting, Can you please make video to list out the patticular value is true / false from axurd congratulations?

  • @drummerboi4eva
    @drummerboi4eva 2 года назад

    very nice video

  • @taycynne8517
    @taycynne8517 Год назад

    Hi I have an question. I am trying to learn KQL however, I would need to know about the reason behind the failed nodes being rebooted... Any Suggestions on what to do? :(

  • @Krishna-md1iu
    @Krishna-md1iu 4 года назад +1

    It was very informative, thanks for this video and key posting more content and KQL

    • @TenMinuteKQL
      @TenMinuteKQL Год назад

      We just started a new channel just for KQL, Ten Minute KQL!

  • @pavantej9666
    @pavantej9666 4 года назад

    Explanation with right examples. Superb. Looking for more video’s on KQL.

    • @TenMinuteKQL
      @TenMinuteKQL Год назад

      We just started a new channel just for KQL, Ten Minute KQL!

  • @sureshkrishnamurthy7739
    @sureshkrishnamurthy7739 3 года назад

    Dana ,is it possible to use KQL in logs generated by azure web apps ?

  • @rajaramarumugam3878
    @rajaramarumugam3878 4 года назад

    Very helpful video, its good start for me

  • @sekhar10330
    @sekhar10330 4 года назад

    Thank you very much, sir can you please correct me below query,
    Q) Find out the list of pipelines which are running more than 40hrs
    ADFPipelineRun
    | join kind = inner (
    ADFPipelineRun
    | where Status == "InProgress") on RunId
    | project TimeGenerated,PipelineName,Start,End,now(),difftime = datetime_diff('hour',now(),Start)
    | where difftime>40
    | order by difftime desc

  • @goyumbod1753
    @goyumbod1753 4 года назад

    Hello, Thank you for this video. I wanna ask a question from you. How do you enable the SecurityEvent data? To collect this data, did you use the Azure Arc? I need to collect the SecurityEvent of workstations at the on-premise.

  • @torajeshtk
    @torajeshtk 4 года назад

    @KnowOps - Is there any tutorial where can I refer the Azure tables? I want to get the listener details of application gateway such as name, created timestamp

  • @deepakrajput0071
    @deepakrajput0071 3 года назад

    Why have you stopped making videos,loved your content

  • @rohitkumarjain1092
    @rohitkumarjain1092 4 года назад

    A big thumps up !! .. your videos are fantastic. Do you also have any course also for Azure or AWS ? would love to learn from it.

  • @naqashahmed3113
    @naqashahmed3113 4 года назад

    Great video. May i know if we can get Azure MFA details using Resource Graph queries?

  • @vinodmahajan4858
    @vinodmahajan4858 4 года назад

    Hello Sir , How I can use multiple aggregate function Count on resultset of table.

  • @ArjunKumar-ls5ow
    @ArjunKumar-ls5ow 4 года назад

    Great presentation !!

  • @thekillbreathfamily7371
    @thekillbreathfamily7371 4 года назад

    I could not get the Perf sample at 12:20 to work. Tried on same demo environment (thanks for url!) and live environment. The first two lines:: Perf | where ObjectName == “System” yields nothing. Perf | project ObjectName | sort by ObjectName asc | distinct ObjectName shows lots of values, but none are “System”. Maybe Microsoft revamped Perf recently? Will need to find a different way to pull Uptime. Great tutorial. Will watch more.

    • @JackSmith-oy7rx
      @JackSmith-oy7rx 3 года назад

      I think these logs are not enabled by default and you need to add perf monitoring logs to your log analytics configuration under Agents configuration > windows peformance counters

  • @balineprem
    @balineprem 4 года назад

    Great video Dana on KQL, could you please let me know how to monitor blocking and long running queries in sql dw using KQL?

  • @Hari-ed5es
    @Hari-ed5es 4 года назад

    Thank you very much. Can you help me with 2 things here.
    -When we pull this application name i can see only 10,000 by default, but i have around 20011838. How do i pull that?
    - For the Audit Logs i need to get last 30 who did some changes? Can you help me with that

  • @tpademo4237
    @tpademo4237 3 года назад

    I need some pointer
    Could you help me on these two questions?
    Q.1) How to get raw payload of incident related events using KQL?
    Q.2) How to get volume of day using API?
    I am new to Sentinel
    Thank You

  • @thepassportog
    @thepassportog 3 месяца назад

    Taking a break after just missing passing AZ 104. Pleasant surprise

  • @nasarazam
    @nasarazam 3 года назад

    Mine does not recognize the "SecuriyEvent" Table !

    • @Davidc10
      @Davidc10 Год назад

      It is case sensitive so make sure you write it exactly like that and without the speech marks. Works for me

  • @ayuanf
    @ayuanf 4 года назад

    Thank you for the video!

  • @nikithacheemati7581
    @nikithacheemati7581 4 года назад

    great video! can you do a demonstration about obfuscation in KQL

    • @KnowOps
      @KnowOps  4 года назад +1

      Great suggestion. Can you give me an example of what you want to see?

    • @nikithacheemati7581
      @nikithacheemati7581 4 года назад

      @@KnowOps thanks for your response. For example, how can we mask(obfuscate) any particular coloumn data which is considered has sensitive information while querying in KQL

  • @TheMLaskowsky
    @TheMLaskowsky 4 года назад

    Great channel. Subscribed ! :)

  • @danieljansen1987
    @danieljansen1987 3 года назад

    Thanks!

  • @abhishekanand2219
    @abhishekanand2219 4 года назад

    i dont knoiw why but i dint get SecurityEvent while running query , i am doing it from free account and runnnig 1 win adn 1 lin vm, However perf is working fine
    In the next video Can you show how we can see these data in the Azure dashboard after we customise it in loganalytics through Kusto queries

  • @uriel4292
    @uriel4292 3 года назад

    Hey Dana, why are you not uploading new vids, been waiting for some new vids. Especially about Advance Threat Hunting using KQL on Microsoft Defender ATP.

    • @TenMinuteKQL
      @TenMinuteKQL Год назад

      We just started a new channel just for KQL, Ten Minute KQL!

  • @juancvr18
    @juancvr18 4 года назад

    Very helpful thanks a lot!!

  • @pinakichakraverty3504
    @pinakichakraverty3504 Год назад

    I need help in Pulling Data from KQL for those sets of Users who have not Enrolled for Phone sign in.. I have KQL for users who have enrolled for Phone sign in via audit logs.. Please please Please help me on finding KQL query for finding Set of Users who have not Enrolled for Phone sign in.. Plzzzz 🙏

    • @TenMinuteKQL
      @TenMinuteKQL Год назад

      We just started a new channel just for KQL, Ten Minute KQL!

  • @alhaponyfarag1464
    @alhaponyfarag1464 5 лет назад

    Thanks Dana

  • @Datapassenger_prashant
    @Datapassenger_prashant 4 года назад

    Hi! Everyone
    Guys, I'm quite new to this language and stuck badly at "partition operator". As my query is returning me error: Query execution has resulted in error (0x80DA0007): Partial query failure: Low memory condition (E_LOW_MEMORY_CONDITION). (message: 'bad allocation', details: '').
    and I'm stuck how to solve the issue.
    If anyone can help me, that will be great.

  • @sukantvirkud
    @sukantvirkud 5 лет назад

    Best explanation and example 👍.... Do you have any contact details so we can reach.....

    • @KnowOps
      @KnowOps  5 лет назад +1

      +Sukant Virkud if you want to reach Dana at work, check out www.auditwolf.com. If you want to ping him personally, check out www.danaepp.com. Both sites have his contact details.

    • @DanaEpp
      @DanaEpp 5 лет назад

      Along with those avenues you can also follow me on Twitter at @danaepp and DM me. All good options. Appreciate you checking out the episode!

  • @tanhazjustdance2024fan4ever
    @tanhazjustdance2024fan4ever 4 года назад

    Excellent presentation - both in content and execution. If you do not mind, could you please tone it down a little bit. Don't get me wrong, I enjoyed the video and learn something but felt like you are shouting. My apologies if I being unreasonable and ignore me.

  • @sweedieman3231
    @sweedieman3231 Год назад

    SQL > KQL

  • @2lotsill
    @2lotsill 11 месяцев назад

    Every time I hear KQL pronounced, I think of Krusty the 🤡