HOTSPOT -
You have an Azure subscription that contains a Log Analytics workspace named Workspace1.
You configure Azure activity logs and Microsoft Entra ID logs to be forwarded to Workspace1.
You need to identify which Azure resources have been queried or modified by risky users.
How should you complete the KQL query? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
kukuliquid
Highly Voted 1 year, 1 month agotrut_hz
5 months, 1 week agouser636
Highly Voted 9 months, 4 weeks agotalosDevbot
8 months, 2 weeks agoOneplusOne
3 weeks, 5 days agoHAjouz
Most Recent 3 months, 3 weeks agoHAjouz
6 months, 1 week agog_man_rap
10 months agoshdwktn
10 months, 3 weeks agosmosmo
1 year agoladdu001
1 year, 1 month ago