02x06-silence_of_the_logs.kql

02x06-silence_of_the_logs.kql

Everyday Defender di Chris & Koos
S2 · E6
1 lug 2026
38:21

Note sull'episodio

In this episode Chris takes a look at Exchange-attribute Source of Authority (SOA) transfer - could this finally be the answer to removing that last Exchange server we've all been waiting for?

Koos has spent years deep in Microsoft Sentinel, and a big chunk of that has been log ingestion and keeping the ingestion bill under control: getting the right data in, keeping the noise out. He promised this wouldn't turn into the Sentinel show, but when Microsoft ships two genuinely new log-ingestion features, he has to talk about them. There are two Azure Monitor previews worth talking about. The first, 'multi-stage transformations', lets you filter and aggregate logs before they're ingested. The second brings platform logs into the Data Collection Rule model, the same way he already collects everything else. He'll cover what's genuinely new, and why he thinks Microsoft perhaps highlighted the wrong features in their blogs.

Full show notes available on our blog: https://df3ndr.io/episodes/2026/07/01/02x06-silence_of_the_logs.kql.html

Follow us on your favorite podcast platform or check us out at https://df3ndr.io