Skip to content

Commit 1a22fa7

Browse files
committed
Updating old Kusto links to new ones
1 parent 9d33535 commit 1a22fa7

File tree

3 files changed

+36
-1
lines changed

3 files changed

+36
-1
lines changed
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
---
2+
title: "include file"
3+
description: "include file"
4+
services: microsoft-sentinel
5+
author: yelevin
6+
ms.author: yelevin
7+
ms.topic: "include"
8+
ms.date: 12/26/2024
9+
ms.custom: "include file"
10+
---
11+
<!-- docutune:disable -->
12+
13+
For more information on KQL, see [Kusto Query Language (KQL) overview](/kusto/query/?view=microsoft-sentinel&preserve-view=true).
14+
15+
Other resources:
16+
- [KQL quick reference](/kusto/query/kql-quick-reference?view=microsoft-sentinel&preserve-view=true)
17+
- [Kusto Query Language learning resources](/kusto/query/kql-learning-resources?view=microsoft-sentinel&preserve-view=true)
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
---
2+
title: "include file"
3+
description: "include file"
4+
services: microsoft-sentinel
5+
author: yelevin
6+
ms.author: yelevin
7+
ms.topic: "include"
8+
ms.date: 12/26/2024
9+
ms.custom: "include file"
10+
---
11+
<!-- docutune:disable -->
12+
13+
> [!NOTE]
14+
> For more information on KQL, see [Kusto Query Language (KQL) overview](/kusto/query/?view=microsoft-sentinel&preserve-view=true).
15+
>
16+
> Other resources:
17+
> - [KQL quick reference](/kusto/query/kql-quick-reference?view=microsoft-sentinel&preserve-view=true)
18+
> - [Kusto Query Language learning resources](/kusto/query/kql-learning-resources?view=microsoft-sentinel&preserve-view=true)

articles/sentinel/siem-migration.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ Current capabilities:
5252

5353
- Map Splunk detections to OOTB Microsoft Sentinel analytics rules.
5454
- Translate simple queries with a single data source.
55-
- Automatic translations of SPL to KQL for the mappings listed in the article, [Splunk to Kusto cheat sheet](/azure/data-explorer/kusto/query/splunk-cheat-sheet).
55+
- Automatic translations of SPL to KQL for the mappings listed in the article, [Splunk to Kusto cheat sheet](/kusto/query/splunk-cheat-sheet?view=microsoft-sentinel&preserve-view=true).
5656
- **Schema Mapping (Preview)** creates logical links for the translated rules by mapping Splunk data sources to Microsoft Sentinel tables, and Splunk lookups to watchlists.
5757
- Translated query review provides error feedback with edit capability to save time in the detection rule translation process.
5858
- **Translation State** indicating how completely SPL syntax is translated to KQL at the grammatical level.

0 commit comments

Comments
 (0)