KQL query to change Azure Sentinel log timestamp format
Analysts forget that Sentinel logs output the TimeGenerated field values as UTC. Add this line to create a reformatted timestamp field congruent to your time zone: Remember to change the amount value to the UTC difference for your time zone. For example, I am in the US Eastern Time Zone, which is -4. Now you … Read more