Home › Glossary › Analytics rule

Analytics rule

KQL-based detection in Microsoft Sentinel that searches ingested data, generates alerts and bundles them into incidents. Rules identify threats but do not fix them.

Read more: Microsoft Learn

In the Ultra Transcenders books

SC-500SC-900SC-200

Each book explains Analytics rule in context, with comparison tables and the common traps.

Terms in this definition

Related terms

See Analytics rule in the full glossary