Un peu de KQL
=~ valeur approx (ne tient pas compte des minuscules/majuscules)SecurityEvent_CL| where TimeGenerated > ago(7d) and EventID_s == 4688| summarize count() by Computer Compter le nombre d’occurence des différents champsSecurityEvent_CL| where TimeGenerated > ago(7d) and EventID_s == 4624| summarize cnt=count() by AccountType_s,…
