KQL Querying for Sentinel: Security Threat Detection Fundamentals
Master Kusto Query Language to analyze security logs, hunt for threats, and configure basic detection rules in Sentinel.
-
💬
ผู้สอน AI
ถามเกี่ยวกับบทเรียนใดก็ได้ แล้วรับคำตอบที่ชัดเจนทันที ทุกเมื่อ -
🕐
เริ่มเมื่อไรก็ได้
ไม่มีตารางหรือเดดไลน์ — เรียนตามจังหวะของคุณ เมื่อไรก็ได้ -
🌐
เป็นภาษาไทย
บทเรียน แบบฝึกหัด และใบรับรอง — ทั้งหมดเป็นภาษาของคุณอย่างครบถ้วน
เกี่ยวกับคอร์สนี้
As cyber threats grow more sophisticated, security analysts must be able to search through massive volumes of log data quickly and accurately. Sentinel relies on Kusto Query Language (KQL) to turn raw log data into actionable security insights, making KQL an essential skill for modern security operations.
This text-based course guides you from absolute beginner to confidently writing your own KQL queries. You will start with core security logging concepts and foundational KQL syntax, then progress to filtering, aggregating, and joining data from multiple sources. By the end of the course, you will be able to construct queries to detect suspicious activities and assist in threat hunting.
What you'll learn:
- Understand foundational Sentinel log structures and basic KQL syntax
- Filter and sort security event logs using operators like where, take, and sort
- Summarize and aggregate data to identify patterns and anomalies in network traffic
- Join and union multiple data tables to correlate security events across different sources
- Apply Advanced Security Information Model (ASIM) parsers for standardized querying
- Optimize query performance to scan large datasets efficiently without wasting resources
We begin with essential security monitoring definitions and the basic structure of the KQL environment. From there, you will read through step-by-step query construction, analyzing real-world security log scenarios through written examples and practical explanations.
This course is designed for aspiring security analysts, system administrators, and IT professionals new to SIEM tools and KQL, with no prior querying experience required.
Start reading today to build the essential querying skills needed to defend your organization's digital assets.
สิ่งที่คุณจะได้รับ
-
📜
ใบประกาศนียบัตร
เพิ่มในโปรไฟล์ LinkedIn ของคุณ -
💬
ติวเตอร์ AI ส่วนตัว
ติดขัดในบทเรียน? ถามติวเตอร์ในตัวของคุณได้ทุกอย่าง ทุกเวลา -
🎧
รวมเวอร์ชันเสียง
เรียนได้ทุกที่ ไม่ต้องดูจอ -
♾️
เข้าถึงตลอดชีพ
กลับมาเรียนได้ตลอด ไม่มีหมดอายุ -
📱
โทรศัพท์หรือคอมพิวเตอร์
ใช้งานได้ทุกที่ ทุกอุปกรณ์ -
💸
คืนเงิน 14 วัน
ไม่ต้องอธิบาย -
⚡
กระชับและตรงประเด็น
2 ชม. 48 นาที เนื้อหาเชิงปฏิบัติ
รีวิว
ยังไม่มีรีวิว — เป็นคนแรกที่แชร์ประสบการณ์
ผู้เรียนคนอื่นเรียน
🎓 มีใบรับรอง
ฐานข้อมูลแบบกระจาย Cassandra: สถาปัตยกรรม, CQL และการจัดการคลัสเตอร์
ใบรับรอง
ลงมือทำ
$49.99
→
🎓 มีใบรับรอง
คู่มือการค้นหา Splunk และการสืบค้น SPL
ใบรับรอง
ลงมือทำ
$49.99
→
🌟 ที่นิยมในหมู่ผู้เรียน
🎓 มีใบรับรอง
เทคโนโลยีฐานข้อมูลยุคหน้าและแนวโน้มในอนาคต
ใบรับรอง
ลงมือทำ
$49.99
→
🔥 เป็นที่ต้องการ
🎓 มีใบรับรอง
ElasticSearch สำหรับระบบค้นหาและแนะนำ
ใบรับรอง
ลงมือทำ
$89.99
→
คำถามที่พบบ่อย
ฉันต้องใช้อะไรในการเรียนคอร์สนี้? +
แค่โทรศัพท์หรือคอมพิวเตอร์ที่มีอินเทอร์เน็ต ไม่ต้องติดตั้งหรือใช้อุปกรณ์พิเศษ
ฉันชำระเงินอย่างไร? +
ผ่านบัตรด้วย Stripe เราไม่เก็บข้อมูลบัตร — Stripe จัดการอย่างปลอดภัย
ฉันขอคืนเงินได้ไหม? +
ใช่ — คืนเงินเต็มจำนวนใน 14 วัน ไม่ต้องอธิบาย
ฉันมีสิทธิ์เข้าถึงนานเท่าไร? +
ตลอดไป เมื่อซื้อแล้วคอร์สเป็นของคุณ กลับมาเรียนได้ตลอด
ฉันจะได้ใบประกาศนียบัตรไหม? +
ได้ เมื่อเรียนจบจะได้รับใบประกาศนียบัตรที่เพิ่มในโปรไฟล์ LinkedIn ได้
ออกแบบสำหรับผู้เรียนใน
เทคโนโลยี
ดีไซน์
การเงิน
การตลาด
สาธารณสุข
การศึกษา
ธุรกิจการบริการ
อุตสาหกรรม
×2
เติมครั้งเดียว จ่ายครึ่งเดียว
เพิ่ม $100 → รับเครดิต 200 เครดิต ทำให้แต่ละหลักสูตรมีราคาประมาณ $12.50 เครดิตไม่มีวันหมดอายุ
$100
200 เครดิต
$12.50 / คอร์ส
คุ้มที่สุด
$250
550 เครดิต
$11.36 / คอร์ส
$500
1200 เครดิต
$10.42 / คอร์ส
เครดิตใช้ได้กับทุกคอร์สและไม่หมดอายุ