List Analytics Rules Failures
Description
This KQL query check for failures in Analytics Rules.
Query
Microsoft Sentinel
Kusto
SentinelHealth
| where TimeGenerated > ago(30d)
| where Status == "Failure"
| where SentinelResourceType == "Analytics Rule"
| where ExtendedProperties !contains "TemporaryIssuesDelay"
| summarize Count=count() by SentinelResourceName, Issue=tostring(ExtendedProperties.Issues)
| project SentinelResourceName, Count, Issue