HOTSPOT
-
You have a Microsoft Sentinel workspace named Workspace1.
You configure Workspace1 to collect DNS events and deploy the Advanced Security Information Model (ASIM) unifying parser for the DNS schema.
You need to query the ASIM DNS schema to list all the DNS events from the last 24 hours that have a response code of ‘NXDOMAIN’ and were aggregated by the source IP address in 15-minute intervals. The solution must maximize query performance.
How should you complete the query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
ultraRunningCA
Highly Voted 1 year, 8 months ago7c0a
1 year, 5 months ago789sv
1 year, 6 months agodalancoburn
1 year, 6 months agoWalaakb
1 year, 8 months agoRamye
Most Recent 9 months, 2 weeks agomspcute
1 year agochepeerick
1 year, 1 month agodanb67
1 year, 1 month agodanb67
1 year, 1 month agodonathon
1 year, 3 months agoJoeP1
1 year, 4 months agodavidli
1 year, 1 month agoomar_alhajsalem
1 year, 6 months agoAlbonzi
1 year, 9 months agoultraRunningCA
1 year, 8 months agoliliap
1 year, 8 months ago