You create a hunting query in Azure Sentinel.
You need to receive a notification in the Azure portal as soon as the hunting query detects a match on the query. The solution must minimize effort.
What should you use?
a playbook
a notebook
a livestream
a bookmark
Explanation:
Use livestream to run a specific query constantly, presenting results as they come in.
Submit