Azure Resource Graph lets you run KQL over deployed resources in many subscriptions at once. Log Analytics and advanced hunting can call it with arg(), while analytics rules and lake queries cannot.
Also called Azure Resource Graph.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains ARG in context, with comparison tables and the common traps.
Terms in this definition
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- Advanced hunting
Threat-hunting feature of the Microsoft Defender portal that runs KQL over 30 days of raw Defender XDR data, plus onboarded Sentinel data, and supports custom detections. It finds activity after it happens rather than blocking it.
Related terms
- SecurityIncident
Each create or update of a Sentinel incident writes another row here, so it suits SOC metrics like time to close or triage. To see only the current state of every incident, summarise with arg_max.