Analytics rules are how Sentinel turns data into alerts and incidents. An alert is a single detection; an incident groups one or more alerts into the unit of work an analyst investigates. The exam expects you to know each rule type, when to use it, and the settings that make its alerts useful to analysts. You create rules under Configuration, Analytics, often starting from a template installed by a Content hub solution. Scheduled rules are the workhorse. You write a KQL query, choose how often it runs (query frequency) and how far back it looks (lookback), and set a threshold, such as generate an alert when the query returns more than zero results. The lookback should usually be at least as long as the frequency so events are not missed, and a little overlap covers ingestion delay. You also choose event grouping: one alert for all results, or one alert per result row. Near-real-time (NRT) rules run about every minute over a very short lookback, for high-priority detections where minutes matter, such as a break-glass account signing in. NRT rules have more limits on query complexity than scheduled rules.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.