edited syntax

This commit is contained in:
Justin Hall 2018-12-05 15:26:34 -08:00
parent f7e6c9d2b8
commit fd65604035

View File

@ -23,7 +23,7 @@ This capability is supported beginning with Windows version 1607.
Here is a simple example query that shows all the WDAC events generated in the last seven days from machines being monitored by Windows Defender ATP: Here is a simple example query that shows all the WDAC events generated in the last seven days from machines being monitored by Windows Defender ATP:
```Kusto ```kusto
MiscEvents MiscEvents
| where EventTime > ago(7d) and | where EventTime > ago(7d) and
ActionType startswith "AppControl" ActionType startswith "AppControl"