Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

KQL (Kusto): Advanced Queries

Premium room

Learn about advanced KQL queries and how to leverage the power of Microsoft KQL.

medium

60 min

395

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

This room is a continuation of the (Kusto): Basic Queries room. However, we will discuss advanced queries, and, as before, we will run as many queries as possible to ensure you are familiar with the different operators and functions for threat analysis. Basic queries provide a good foundation for security analysis in Microsoft Sentinel, but for in-depth threat hunting and incident investigation, advanced knowledge is required.

Prerequisites

Learning Objectives

  • How to use the join operator
  • How to use the union operator
  • How to use the project operator
  • How to use the extend operator
  • How to create parsers and use the parse operator
Answer the questions below
I am ready to go advanced!

Ready to learn Cyber Security?

The KQL (Kusto): Advanced Queries room is only available for premium users. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.

Already have an account? Log in

We use cookies to ensure you get the best user experience. For more information see our cookie policy.