Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Save julian-wendt/b030a0168133307ed9b94c0d1ac77795 to your computer and use it in GitHub Desktop.
Save julian-wendt/b030a0168133307ed9b94c0d1ac77795 to your computer and use it in GitHub Desktop.
Add alert evidence details as key value pair
AlertEvidence
| mv-apply ParsedFields = parse_json(AdditionalFields) on
(
extend Key = tostring(bag_keys(ParsedFields)[0])
| project Key, Value = ParsedFields[Key]
)
| project-away AdditionalFields
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment