Тёмный
TeachJing
TeachJing
TeachJing
Подписаться
Visit my browser desktop @ www.teachjing.com
Follow me on twitter or LinkedIn @ TeachJing.
Security Reports Gallery with PowerBI!
13:12
3 года назад
Комментарии
@surya9900k
@surya9900k 2 дня назад
SecurityAlert Logs are not getting pulled up
@trinity6880
@trinity6880 16 дней назад
thank you very much man!! :D
@dongodilorica6037
@dongodilorica6037 17 дней назад
Nice work. Thanks senpai.
@gliceriojrlajara4329
@gliceriojrlajara4329 27 дней назад
Could ypu make new syslog/cef firwarder lab seiries with the new sentinel ama connector?
@jwild1979
@jwild1979 Месяц назад
Why containers not VMs? Total noob here. I went from picking up a few WI. Fi smart bulbs to deciding Hey and at home. Automation would be better than the cloud apps. 2, Hey, I need to build myself a home lab computer to run. Home assistant, and now i'm here and I don't know how I got here and yeah
@AmadouMANE-rt4rz
@AmadouMANE-rt4rz Месяц назад
create alerts, use look up file, long query also is good
@mr.sevent.7557
@mr.sevent.7557 Месяц назад
I honestly see this video being helpful with repetition. Thanks 🙏🏿
@infosec4391
@infosec4391 Месяц назад
Yes, really good stuff, but the isnotnull doesn't work for strings. isnotempty works better for the description.
@olafhoogstad446
@olafhoogstad446 3 месяца назад
Good morning :) A BIG thank you from me for explaining KQL so well and in an easy to understand way! You ae a KQL life saver for me :)
@benb8291
@benb8291 3 месяца назад
man this is way better than all the udemy courses lol awesome job bro
@2223ams
@2223ams 3 месяца назад
Thanks a lot for this. I'm a non-tech person retraining on a network+ prep course that's insanely fast-paced and not particularly well organized. Thankfully, the instructor included your video as part of the workbook and it actually made sense to me. I appreciate you man.
@simple-security
@simple-security 4 месяца назад
great video but it's now obsolete. consider a new on on the AMA agent.
@timdryer
@timdryer 4 месяца назад
When 900 years old you reach, code this good you will not!!
@rahmanmahmoodi8573
@rahmanmahmoodi8573 5 месяцев назад
What book is this please?
@fingerw
@fingerw 6 месяцев назад
This was a good video - I can always used a cheat sheet.
@zakecysec
@zakecysec 6 месяцев назад
my rsyslog.conf not same like you, did i need to update it manual or what i must to make it easier ?
@zakecysec
@zakecysec 6 месяцев назад
tail: cannot open 'messages' for reading: No such file or directory help
@LegoDinoMan
@LegoDinoMan 6 месяцев назад
Wow, that's incredible. Thank you for sharing!
@simple-security
@simple-security 6 месяцев назад
any updates on your BI > Sentinel dashboards?
@TheTerminator317
@TheTerminator317 6 месяцев назад
I am little confused with arg_max function still. From what I understood was arg_max will return maximum value for whatever column is in the bracket. For example let's say I have following simple query. This will return single row as result of latest value as we're passing TimeGenerated in brackets to arg_max SecurityEvent | where TimeGenerated > ago(1d) | summarize arg_max(TimeGenerated, *) But when I replace this with following query, it gives me multiple results. SecurityEvent | where TimeGenerated > ago(1d) | summarize arg_max(TimeGenerated, AccountType, Activity) by Account So this is kinda confusing me as it's not giving just maximum value but multiple results. Is it because of what you explained at around @ 16.21 in this video?? So far I am finding your tutorials helpful in understanding KQL better as this is something that has always challenged me within Azure..
@RahulSingh-r6t
@RahulSingh-r6t 6 месяцев назад
What is the headset you are using? 🙂
@happysigmass
@happysigmass 7 месяцев назад
Today my school had gotten hacked and it was because these kids were going on bad websites and the firewall got open and hackers were able to get into all our computers and find our information. But it’s was only in middle school so elementary kids were fine. They did change the password though which I don’t know if that did anything tbh
@navisionator2854
@navisionator2854 7 месяцев назад
A great tutorial. Many thanks for it 😃
@jonathonstufflebeam7433
@jonathonstufflebeam7433 7 месяцев назад
My jam
@zaki-x6r
@zaki-x6r 8 месяцев назад
Why i don't have message file in /var/log ?
@yusareba
@yusareba 8 месяцев назад
Can this be done for free? I'm interesting in doing this but assume it has costs associated
@rajeshravichandran2170
@rajeshravichandran2170 8 месяцев назад
Thanks brother for this KQL tutorial videos. It is helpful
@taofeekadisa7619
@taofeekadisa7619 8 месяцев назад
How can I automate this process with power automate or any other tool?
@allwayshype
@allwayshype 8 месяцев назад
Thank you so much for doing this series! It’s helped me SO much!
@riadoszh6616
@riadoszh6616 8 месяцев назад
nice video! it was very useful and very interesting :) your content is very informative. thank you for your valuable contribution! please keep going!
@sergiocarmona7238
@sergiocarmona7238 9 месяцев назад
one question can you make subqueries in KQL and join?
@TeachJing
@TeachJing 9 месяцев назад
Yes a couple ways to achieve. One example is to embed the subquery in parenthesis when you join it. Just need a common reference common between both tables
@GetFitStayFit1
@GetFitStayFit1 9 месяцев назад
How would I import the samples into the powerbi or load up the samples as you're showing. Can you do a video on that process
@ericmyrs
@ericmyrs 9 месяцев назад
This is pretty cool but that's not how groups in regex works. 0 is the whole match but without regex syntax, 1 is the first group, 2 is the second etc. if you do match "thing (one) (two)" then 0 returns " thing one two", 1 returns one, and 2 returns two.
@xaviercortez5625
@xaviercortez5625 10 месяцев назад
I subscribed because of the animation. Will be watching from the beginning of the playlists. Good stuff to capture attention.
@jimtaylor4938
@jimtaylor4938 10 месяцев назад
What about the AMA agent ?
@darrensmith5544
@darrensmith5544 10 месяцев назад
Good vid!
@rmp5s
@rmp5s 11 месяцев назад
Great vid, my dude. Would love to see an updated video with the new AMA agent. OMS is going away. For some reason.
@sdrawkcab8911
@sdrawkcab8911 11 месяцев назад
Great video, also just wanted to let you know that I was sent here by one of your interns. 😂
@atul2651
@atul2651 11 месяцев назад
Thanks for the video, quick query: Is there anyway to join more than 2 tables ?
@nsomba
@nsomba Год назад
Hello @Teachjing, All your tutorials are very helpful I know my question might be two years late but the "protectionstatus" table no longer seems to have no sample data work with . I am trying to work with your instructions but the "protectionstatus" table within the database "security and audit " has no sample data so what would you suggest we use as an alternative ?
@Compy-m4g
@Compy-m4g Год назад
Studying for my SC-200 as of current! This has come in so much help, I think I am primarily struggling with the tables and filters, and just understanding the processes, any tips to simplify this or how to learn this any quicker from a non-technical background.
@TeachJing
@TeachJing Год назад
Just imagine water. When you filter the water, the output of that water can be filtered again. This can be chained as many times as you want to get to the output you desire. Water -> remove sand -> remove bacteria -> add bleach -> boil it -> desired water state. In KQL the output of a result can be filtered again by adding another pipe “|”. You can pipe as many times as you want which doesn’t look very nice but still gets the job done 😀 Table | filter by certain time | filter by certain hostname | summarize by event count | desired output One key note to know is you can’t unfilter what you have filtered just like water, but you can move the sequence around. An example is you typically want to summarize at the end. If you do it in the beginning, you may not have the desired result you want.
@willmclean8743
@willmclean8743 Год назад
@@TeachJinghighly appreciate this! Thank you so much for the series and the information!
@trendyniro
@trendyniro Год назад
Thank you so much Teachjing! you gave me loads of info!...
@GiscardYoryor-x1d
@GiscardYoryor-x1d Год назад
Hi Sir. Thanks for you great work. I have learned a lot from your videos. However, there is one thing I can’t seem to figure out. I want to run a query where the data is found in 2 different tables (SecurityAlert & SigninLogs). The common column in both tables is “UsedId”. How can I use join or union operator to put these 2 tables together and get my data. The common column in the 2 tables is “UsedId” SecurityAlert | where AlertName == "Unfamiliar sign-in properties" | where AlertSeverity == "High" SigninLogs | where RiskState == "atRisk"
@TeachJing
@TeachJing Год назад
I made a video on joins ! That will solve your scenario and you would reference that common tables
@Sharlie909
@Sharlie909 Год назад
Nice vid!!! 🦾
@Burco20007
@Burco20007 Год назад
Regarding the difficulty level, I must say that it was just right for me. The material was presented in a way that was challenging enough to keep me engaged but also manageable to grasp. I'm glad to hear that it will get better as the series progresses, and I'm excited to continue learning. Once again, thank you for your dedication to teaching and your willingness to assist learners. I truly appreciate the support and look forward to continuing this journey with your valuable guidance. Once again, thank you for your dedication to teaching and your willingness to assist learners. I truly appreciate the support and look forward to continuing this journey with your valuable guidance.