Skip to main content

Get hands-on with analysing security logs to detect and investigate threats efficiently using KQL.

Kusto Query Language (KQL) is a highly efficient, read-only query language used in various Microsoft services, such as Azure Data Explorer, Azure Monitor, and Microsoft Sentinel. This makes it accessible to analysts, developers, and IT professionals for querying log data. This module will help you become more comfortable using KQL query syntax, from basic to advanced level queries, to analyze logs from different sources and detect anomalies using various KQL operators and functions.

What are modules?

A learning pathway is made up of modules, and a module is made of bite-sized rooms (think of a room like a mini security lab).

Hierarchical diagram showing how learning pathways contain modules, which contain individual rooms.