Configured KQL not working properly – CiscoISE event 60095 and 60098
I have a default KQL below which is used to detect when Cisco ISE failed backup, it fires an alert in Sentinel.
But it is not working as expected – it does fire an alert, but returning a timestamp only.
Nonetheless, I can see it is also su… Continue reading Configured KQL not working properly – CiscoISE event 60095 and 60098