Livestream for Azure Sentinel [General Availability]
What is Azure Sentinel Livestream?
Livestream lets you run queries that refresh every 30 seconds and notifies you of any new results. Creating a livestream enables you to :
- test newly created queries as events occur,
- receive notifications from a session when a match is found,
- promote a livestream to a detection rule to generate incidents in the future,
- quickly launch investigations if necessary.
You can quickly create a livestream session using any Log Analytics query.