Cross-Workspace KQL and ASIM Strategy
Cross-workspace KQL lets managed security teams query Sentinel and Log Analytics data across customer or regional workspaces, while ASIM parsers normalize source-specific tables into common schemas for portable detections and hunts.
capabilitiesCurrent
Relationships
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Supported | Reference |
| REST API | Supported | Reference |
| Graph | Gap | Sentinel workspace KQL is queried through Azure Monitor Logs, not Microsoft Graph. |
| ARM | Supported | Reference |
| Bicep | Supported | Reference |
| Terraform | Supported | azurermazurerm_log_analytics_saved_search Reference Terraform can deploy saved searches and Sentinel rule queries, but query authoring and ASIM parser design remain KQL content work. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |