Microsoft Sentinel medium experimental kql
Commvault Cloud Alert
'This query identifies Alerts from Commvault Cloud.'
Detection Logic
CommvaultAlertsCCF_CL
| where TimeGenerated > ago(5m)
| where isnotnull(AnomalyType) and AnomalyType > 0
| take 1000 Field Validations
Loading…
Comments (0)
Loading comments...