Skip to content
Using KQL for Audit Log Analysis in Entra ID

Using KQL for Audit Log Analysis in Entra ID

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

The articles discuss the use of KQL (Kusto Query Language) for analyzing audit logs in Entra ID. One article focuses on troubleshooting function inputs in KQL, while the other details querying user removals from an Entra ID group using audit logs sent to a Log Analytics workspace. Both highlight practical applications of KQL in cybersecurity operations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)