Jun 06 2024 06:36 AM
Hey guys,
I have a problem understanding how Sentinel works. In my Sentinel, I can search for incidents dating back to the year 2022. However, when I try to find the same incidents with a Kusto query, it returns no results. Interestingly, when I attach a tag to one of these old incidents, it pops up in my query search. It feels like there are other tables that we cannot query or some settings are not correctly configured in my instance.
Does anyone know where I can find some information about this issue?
Big thanks,
Joe
Jun 07 2024 02:19 AM
Jun 07 2024 03:29 AM
Jun 07 2024 05:35 AM
SolutionJun 19 2024 12:20 AM
@JoePander Many Thanks for letting me know. I might try that approach. @ 3titik
Jun 07 2024 05:35 AM
Solution