added syntax

This commit is contained in:
Justin Hall
2018-12-05 12:49:13 -08:00
parent 5a9137a094
commit fa5c3d18d5

View File

@ -23,7 +23,7 @@ This capability is supported beginning with Windows version 1607.
Here is a simple example query that shows all the WDAC events generated in the last seven days from machines being monitored by Windows Defender ATP: Here is a simple example query that shows all the WDAC events generated in the last seven days from machines being monitored by Windows Defender ATP:
``` ```kusto
MiscEvents MiscEvents
| where EventTime > ago(7d) and | where EventTime > ago(7d) and
ActionType startswith "AppControl" ActionType startswith "AppControl"