This guide will show you how to run a sample query in the Azure Portal.
Remember that to run a sample query you must set up a Log Analytics workspace in Configuration Manager.
To run a sample query, follow the steps below:
- Navigate to Log Analytics Workspaces in portal.azure.com
data:image/s3,"s3://crabby-images/ce9eb/ce9eb44782c8c56fb5fb37031539ccaae8c83e27" alt=""
- Select the desired workspace, which, in our case, will be the “SimeonCloud” workspace
data:image/s3,"s3://crabby-images/ada3d/ada3db428d0bfb218882ab98d459e0e083bf432b" alt=""
- Go to “logs” and close the “Queries hub” pop up
data:image/s3,"s3://crabby-images/5fc53/5fc536eee9c22821eec057f7238d352a3ae57ee0" alt=""
- Add the KQL (Kusto Query Language) query, for example conditional access policy changes
data:image/s3,"s3://crabby-images/94f85/94f854143684629aa7f1541bf486b494fd50a6e9" alt=""
- Select the Time range
- Run the query
data:image/s3,"s3://crabby-images/9b0e8/9b0e8dc63783f4b9d89807cc093af750bdc90f7a" alt=""
The query will return results, if successful.
data:image/s3,"s3://crabby-images/e22fd/e22fd9ec01f61f358ec772e049f443878d92a253" alt=""
As the query has returned results, we can proceed with creating our custom alert.