capability

Cross-Workspace KQL and ASIM Strategy

Cross-workspace KQL lets managed security teams query Sentinel and Log Analytics data across customer or regional workspaces, while ASIM parsers normalize source-specific tables into common schemas for portable detections and hunts.

capabilitiesCurrent

Relationships

Configuration Methods

MethodSupportReference or Gap
PortalSupported Reference
PowerShellSupported Reference
REST APISupported Reference
GraphGapSentinel workspace KQL is queried through Azure Monitor Logs, not Microsoft Graph.
ARMSupported Reference
BicepSupported Reference
TerraformSupportedazurermazurerm_log_analytics_saved_search Reference

Terraform can deploy saved searches and Sentinel rule queries, but query authoring and ASIM parser design remain KQL content work.

GitHub ActionsSupported Reference
Azure DevOpsSupported Reference