Working with livestream
Livestream is a new feature for Microsoft Sentinel that will allow you to watch one or more hunting queries in real time, to see new results as they occur. This can be useful when performing an investigation and watching whether a query has any new results without having to constantly rerun the query.
Looking back at Figure 11.8, the last entry in the context menu is called Add to livestream. Selecting this will add the query to the Livestream window, as follows:
For each livestream that has been added, you can see its status, the query name, how long it has been running, how many results have been found, what the last result was, the time that the last result occurred, and a sparkline showing how many results were found along the timeline (not shown).
Clicking on each livestream will show the details pane where you get information about the query, including the full KQL code and...