edited syntax

This commit is contained in:
Justin Hall
2018-12-05 13:02:25 -08:00
parent fa5c3d18d5
commit f7e6c9d2b8

View File

@ -23,7 +23,7 @@ This capability is supported beginning with Windows version 1607.
Here is a simple example query that shows all the WDAC events generated in the last seven days from machines being monitored by Windows Defender ATP:
```kusto
```Kusto
MiscEvents
| where EventTime > ago(7d) and
ActionType startswith "AppControl"