This document helps to create clean and readable KQL code for parsing and detection rules.
All views are my own based on writing lots of code in PowerShell and other languages.
This is a living document that helps to create a common baseline.
- Place a spaces before and after the '=' character for readability.
- allign the code using instead of spaces. Keep the '=' character and default values alligned.