Microsoft Sentinel Logs & Writing Queries (part 3 of 3)
The Results Window
The results window header
The table tab
- Display time- It provides you the information of the time zone to show the time in the results window. You can change it with the help of drop-down menu or use Settings section to know how to change it for all the results window.
- Copy request ID- This button is located on the far right side and can provide GUID representing the request copied into the clipboard. It will come in handy if you ever want to contact Microsoft for support to easily locate the query and assist you.
There is a listing of the results column required to be shown, below the grouping area. You can simply click on the name of the column to sort the results which will sort in ascending order for the first time while in descending order next time.
The result footer
As the name suggests, it is located at the bottom of the screen which can allow you to page forward as well as back through your results, show you which page number you are on, and change how many items can be shown on the page for this particular result window. Its parts are described below-
- The go to the first page button will take you to the first page results and is active only when you have more than one page of results while you are not on the first page of results.
- The X listing depicts the the current page you are on and Y one represents total number of pages.
- The go to the next page button simply take you to the next page of results which is active only if you have more than one page of results and you are not on the last page of results.
- The go to the last page button simply take you to the last page of results which is active only if you have more than one page of results and you are not on the last page of results.
- The drop-down menu for items per page helps you to change the number of rows the results are shown on this particular page of results. You can choose 50, 100, 150 or 200 items per page.
The chart tab
If you want to view the results graphically, you can select the Chart tab. A drop-down menu present can change the type of chart shown which can be named after the currently selected graphical choice, but the fields will differ after that.
Comments
Post a Comment