Hunt for anomalies in Sentinel
Description
The anomalies table contains anomalies generated by the active Anomaly analytics rules in Azure Sentinel. Those anomalies do not trigger a incident by default (at the moment of writing). This query lists the anomalies and the reaons why they are anomalies.
Query · kql
let TimeFrame = 7d; Anomalies | where TimeGenerated > ago(TimeFrame) | extend DetailedResultsKQL = ExtendedLinks[0].DetailBladeInputs | project-reorder TimeGenerated, Description, UserPrincipalName, RuleName, Tactics, DetailedResultsKQL, Entities