Memory hook: Scan history deliberately; keep summaries tied to raw evidence.
Must remember
Data-lake hunting separates long-term evidence exploration from the latency needs of operational detections. A KQL job can query supported data-lake data and materialize useful results according to its configured destination and schedule. Check permissions, time range, query limits and expected processing cost before launching a broad historical scan.
Summary rules create preaggregated tables for repeated analysis. Choose bins, dimensions and retained identifiers around the questions analysts must answer. A daily count is fast to query but cannot reconstruct every original process event. Keep a route from suspicious summaries back to raw data.
Search jobs retrieve relevant historical records through their supported search mechanism; they are different from a continuously running near-real-time detection. Distinguish the selected table/tier and query feature instead of assuming every interactive query supports the same retention range.
Notebooks combine code, data access, visualization and analytical workflows. They can support enrichment and complex hunting, but require dependency, identity, data handling and output review. Reproducibility needs saved code, parameter/time-range records and controlled environments; a screenshot alone is weak evidence.
Microsoft Sentinel's MCP support exposes supported capabilities to authorized AI clients. It does not give a model unrestricted permission or make its reasoning reliable. Scope the identity and tools, inspect retrieved evidence, and require appropriate human control over consequential response. Treat log content as untrusted data, including text that looks like an instruction to an agent.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Repeat a costly historical aggregation | A scheduled summary/job with appropriate retained detail. |
| Explore complex evidence with code and visualizations | A governed notebook. |
| AI client needs Sentinel context | Supported MCP access with scoped identity and verified evidence. |
Traps
- A summary table may omit the raw evidence needed to prove an event.
- An AI tool connection does not make log text trustworthy instructions.
Active recall
1. Why use summaries?
To reduce repeated scan work for well-defined recurring questions.
2. What does aggregation lose?
Detail not retained in grouping keys or aggregate outputs.
3. Why record notebook parameters?
To reproduce the investigation and its time/data scope.
4. Why distinguish search from detection?
Historical retrieval does not provide the same continuous low-latency alert behavior.
5. What constrains an MCP client?
Authorized identity, exposed tool capabilities, platform permissions and appropriate human review.