List of questions
Related questions
Question 159 - SC-200 discussion
You have a Microsoft Sentinel workspace.
You have a query named Query1 as shown in the following exhibit.
You plan to create a custom parser named Parser 1. You need to use Query1 in Parser1. What should you do first?
A.
Remove line 2.
B.
In line 4. remove the TimeGenerated predicate.
C.
Remove line 5.
D.
In line 3, replace the 'contains operator with the !has operator.
Your answer:
0 comments
Sorted by
Leave a comment first