Skip to content

KQL for Microsoft Sentinel investigations

Write and read Kusto Query Language (KQL) for real investigations: shape results with where, project, extend and summarize; match strings correctly with ==, =~, in, has and contains; find the latest row with arg_max; and combine tables with let and join, including leftanti. Syntax follows Microsoft's KQL reference.

Level
Intermediate
Length
About 55 minutes
Contents
3 lessons · final exam
Status
Published · updated 1 Oct 2026
  • Microsoft Sentinel

Skills you'll practise

  • Write a query that filters on time first and returns only the columns needed
  • Choose the right string operator (==, =~, in, in~, has, contains) and explain the difference between term and substring matching
  • Summarize results with count(), dcount(), make_set() and arg_max() to answer investigation questions
  • Use let and join, including the default innerunique and leftanti kinds, to combine tables
  • Find and fix common query errors such as columns dropped by project and case-sensitive comparisons

Course outline

  1. 1.Shaping results: filter, pick, calculate, summarizeLesson · 18 min
  2. 2.Matching strings correctlyLesson · 17 min
  3. 3.Combining tables with let and joinLesson · 20 min
  4. 4.KQL for Microsoft Sentinel investigations: knowledge checkKnowledge check · 14 questions
  5. 5.MFA prompts, then a sign-in from abroadScenario
  6. 6.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.