Analytics
Synthetic cases
Expected alerts
Tuning cases
Pass rate
KQL query
Incident timeline
| Time | Table | Account | IP | Host/App | Action |
|---|
Synthetic table rows
| TimeGenerated | Table | Primary entity | IP | Result/Event | Details |
|---|
Guided SIEM view for synthetic Windows SecurityEvent, Entra SigninLogs and AuditLogs correlations.
Synthetic lab only. No Azure tenant, Log Analytics workspace, credentials, tokens, production logs or live Sentinel calls.
| Time | Table | Account | IP | Host/App | Action |
|---|
| TimeGenerated | Table | Primary entity | IP | Result/Event | Details |
|---|