Log Querying in Sentinel with KQL — WalkSelf
⏱ 2 h 48 min 📚 28 leçons 🎧 Version audio

Log Querying in Sentinel with KQL

Master the fundamentals of searching, filtering, and analyzing security data in Sentinel using Kusto Query Language (KQL) to find and investigate threats.

  • 💬 Instructeur IA
    Posez une question sur n'importe quelle leçon et obtenez une réponse claire à tout moment.
  • 🕐 Commencez quand vous voulez
    Sans horaires ni délais : apprenez à votre rythme, quand vous voulez.
  • 🌐 En français
    Leçons, exercices et certificat : tout entièrement dans votre langue.

À propos de ce cours

In today's cybersecurity landscape, the ability to quickly search and analyze massive volumes of security data is crucial for defending your organization. Sentinel provides powerful logging capabilities, but unlocking their value requires knowing how to query that data effectively. This text-based course guides you through the foundational concepts of writing and running queries in Sentinel. You will transition from a complete beginner to confidently constructing Kusto Query Language (KQL) queries to isolate security events, analyze trends, and identify potential threats in your logs. What you will learn: Understand the core architecture of Sentinel logs and how data is structured; Write basic to intermediate KQL queries to filter, sort, and format security log data; Apply essential operators like project, where, extend, and summarize to manipulate datasets; Analyze security events using multi-table joins and unions for deeper correlation; Use modern security parsing standards to normalize data across different log sources; Optimize query performance to search through large-scale datasets efficiently. The course begins with essential security logging terminology and the structure of Sentinel tables. You will then progress step-by-step through practical written tutorials and query examples, building up to multi-table analysis and real-world threat hunting scenarios. This course is designed for aspiring security analysts, system administrators, and IT professionals who are new to Sentinel and KQL, with no prior querying or database experience required. Start reading today to build your foundational security querying skills.

Ce que vous recevez

  • 📜 Certificat de fin
    Ajoutez-le à votre profil LinkedIn
  • 💬 Tuteur AI personnel
    Bloqué sur une leçon ? Pose n'importe quelle question à ton tuteur intégré, à tout moment.
  • 🎧 Version audio incluse
    Apprenez en déplacement, sans écran
  • ♾️ Accès à vie
    Revenez quand vous voulez, sans expiration
  • 📱 Téléphone ou ordinateur
    Fonctionne partout, sur tout appareil
  • 💸 Remboursement 14 jours
    Sans poser de questions
  • Court et ciblé
    2 h 48 min de contenu pratique

Avis

Pas encore d'avis — soyez le premier à partager votre expérience.

Écrire un avis

Nous vous demanderons de vous connecter après envoi — votre brouillon est sauvegardé.

Autres apprenants ont aussi suivi

Questions fréquentes

De quoi ai-je besoin pour suivre ce cours ? +

Un téléphone ou un ordinateur avec internet, c'est tout. Aucune installation, aucun matériel spécial.

Comment payer ? +

Par carte via Stripe. Nous ne stockons pas les données de carte — Stripe les gère de manière sécurisée.

Puis-je obtenir un remboursement ? +

Oui — remboursement complet sous 14 jours, sans question.

Combien de temps aurai-je accès ? +

À vie. Une fois acheté, le cours est à vous, vous pouvez y revenir quand vous voulez.

Vais-je obtenir un certificat ? +

Oui. À la fin, vous recevez un certificat à ajouter à votre profil LinkedIn.

Conçu pour les apprenants en
Tech Design Finance Marketing Santé Éducation Hôtellerie Industrie