Query Details
//Show how many alerts have been generated by a specific service. Example here is MCAS. Change Product to the service you want info on. SecurityIncident | extend Product = todynamic((parse_json(tostring(AdditionalData.alertProductNames))[0])) | where Product has "Microsoft Cloud App Security" | summarize count() by tostring(AlertIds) | summarize sum(count_)
This query shows the number of alerts generated by a specific service, such as Microsoft Cloud App Security. It first extracts the service name from the AdditionalData field, then filters for alerts related to that service. Finally, it calculates the total count of alerts and provides the sum of those counts.

Rod Trent
Released: February 17, 2021
Tables
Keywords
Operators