Skip to content

Conversation

@TheAlistairRoss
Copy link
Contributor

Required items, please complete

Change(s):

Reason for Change(s):

  • Provided a let variable to adjust the dcount accuracy argument with ease.
  • Also set the "| where TimeGenerated" to use a between operator. When looking at the events from incidents within Sentinel (By selecting "Link to LA"), the query is evaluating logs from the 7 days preceding the original analytic rule run datetime to the current day, resulting in inaccurate representation of the events at that given time.

Version Updated:

  • Yes

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

Provided a let variable to adjust the dcount accuracy argument with ease. 

Also set the "| where TimeGenerated" to use a between operator. When looking at the events from incidents within Sentinel (By selecting "Link to LA"), the query is evaluating logs from the 7 days preceding the original analytic rule run datetime to the current day, resulting in inaccurate representation of the events at that given time.
@TheAlistairRoss TheAlistairRoss requested review from a team as code owners April 7, 2025 14:13
@v-atulyadav v-atulyadav self-assigned this Apr 8, 2025
@v-atulyadav v-atulyadav added the Solution Solution specialty review needed label Apr 8, 2025
@v-atulyadav v-atulyadav merged commit 5912b5d into Azure:master Apr 9, 2025
35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants