Microsoft Sentinel medium experimental kql

Commvault Cloud Alert

'This query identifies Alerts from Commvault Cloud.'

View Source

Detection Logic

CommvaultAlertsCCF_CL
| where TimeGenerated > ago(5m)
| where isnotnull(AnomalyType) and AnomalyType > 0
| take 1000

Field Validations

Loading…

Comments (0)

Loading comments...