Summary
In this chapter, we explored the Logs page of Microsoft Sentinel. We saw how to use the various sections of the page, such as the page header, the Tables pane, the Filter pane, and the code and results pages to run built-in queries and determine the way results are displayed. Besides this, we also learned how to write our own queries using KQL.
With the help of the Logs page and by writing useful queries, you are now ready to carry out your own table analysis for investigation. You can use it to your advantage for trend analysis, visualizations, and troubleshooting.
In the next chapter, you will learn how to take the queries you build in the Logs page and use them in analytics queries.