HOTSPOT -
You have an Azure subscription that contains a Log Analytics workspace named Workspace1.
You configure Azure activity logs and Microsoft Entra ID logs to be forwarded to Workspace1.
You need to identify which Azure resources have been queried or modified by risky users.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
kukuliquid
Highly Voted 1 year, 3 months agotrut_hz
7 months, 1 week agouser636
Highly Voted 11 months, 4 weeks agotalosDevbot
10 months, 2 weeks agoOneplusOne
2 months, 3 weeks agoHAjouz
Most Recent 5 months, 3 weeks agoHAjouz
8 months, 1 week agog_man_rap
12 months agoshdwktn
1 year agosmosmo
1 year, 2 months agoladdu001
1 year, 3 months ago