mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-15 14:57:23 +00:00
update adv reference
This commit is contained in:
parent
cf18ce43b0
commit
25237e7de4
@ -27,15 +27,6 @@ ms.date: 04/16/2018
|
|||||||
|
|
||||||
>Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink)
|
>Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhuntingref-abovefoldlink)
|
||||||
|
|
||||||
## Advanced hunting query best practices
|
|
||||||
The following best practices serve as a guideline of query performance best practices and for you to get faster results and be able to run complex queries.
|
|
||||||
- Use time filters first. Azure Kusto is highly optimized to utilize time filters. For more information, see [Azure Kusto](https://docs.microsoft.com/connectors/kusto/).
|
|
||||||
- Put filters that are expected to remove most of the data in the beginning of the query, following the time filter.
|
|
||||||
- Use 'has' keyword over 'contains' when looking for full tokens.
|
|
||||||
- Use looking in specific column rather than using full text search across all columns.
|
|
||||||
- When joining between two tables - choose the table with less rows to be the first one (left-most).
|
|
||||||
- When joining between two tables - project only needed columns from both sides of the join.
|
|
||||||
|
|
||||||
|
|
||||||
## Advanced hunting table reference
|
## Advanced hunting table reference
|
||||||
When you run a query using Advanced hunting, a table with columns is returned as a result.
|
When you run a query using Advanced hunting, a table with columns is returned as a result.
|
||||||
|
@ -47,6 +47,7 @@ The following features are included in the preview release:
|
|||||||
Windows Defender ATP supports the onboarding of the following servers:
|
Windows Defender ATP supports the onboarding of the following servers:
|
||||||
- Windows Server 2012 R2
|
- Windows Server 2012 R2
|
||||||
- Windows Server 2016
|
- Windows Server 2016
|
||||||
|
- Windows Server, version 1803
|
||||||
|
|
||||||
- [Create and build Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)<br>
|
- [Create and build Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)<br>
|
||||||
Windows Defender ATP supports the use of Power BI data connectors to enable you to connect and access Windows Defender ATP data using Microsoft Graph.
|
Windows Defender ATP supports the use of Power BI data connectors to enable you to connect and access Windows Defender ATP data using Microsoft Graph.
|
||||||
|
Loading…
x
Reference in New Issue
Block a user