Using #AzureSentinel and #LogAnalytics you can use a data export rule to dedupe security logs to be sent to Azure Storage for audit and long term retention. Using a #PowerShell script you can operationalize and get back a base KQL query to use on searching against the security logs in Azure Storage.
Tooling:
https://github.com/Azure/Azure-Sentin...
Articles:
https://swiftsolves.substack.com/p/az...
&
https://swiftsolves.substack.com/p/op...
For more content check out: https://linktr.ee/swiftsolves