KQL snippet: find risky tool actions from an AI agent
A short query to isolate write-capable tool calls, their execution identity and correlation before disabling an AI agent.
Read article
Tag
30 articles connected to this technical signal.
A short query to isolate write-capable tool calls, their execution identity and correlation before disabling an AI agent.
Read articleA short query to isolate rule, field, URI and examples before proposing a targeted WAF exclusion.
Read articleA short query to separate missing consumption, retries, poison messages and access errors on a private Storage Queue.
Read articleA short query to find writes, deletes and destination changes that explain a sudden disappearance of logs.
Read articleA short query to separate subscription or key issues, private backend routing, APIM policy failure and application-side API errors.
Read articleA short query to separate application rule denial, network rule denial and DNS proxy resolution before adding an overbroad rule.
Read articleA short query to separate unavailable backend, application failure and WAF blocking when Application Gateway returns 502s on a private path.
Read articleAn operational runbook for Azure Service Bus private access incidents by separating DNS, Private Endpoint, identity, firewall, metrics, logs and rollback.
Read articleA short query to separate missing connection evidence, identity denial, expired SAS and processing errors during a private Service Bus incident.
Read articleAn operational runbook for Azure SQL private access failures by separating DNS, Private Endpoint, firewall, identity, SQL logs and rollback evidence.
Read articleAn operational runbook for Azure Storage private access failures by separating DNS, Private Endpoint, firewall, identity, logs and rollback evidence.
Read articleBuild an operational runbook for App Service private access failures by separating DNS, Private Endpoint, access restrictions, Application Gateway, application logs and rollback evidence.
Read articleA short query to separate WAF, gateway, private DNS, access restrictions and App Service logs during a private access incident.
Read articleBuild an operational runbook for private Azure Functions failures by separating DNS, Private Endpoint, access restrictions, private storage, Application Insights logs and rollback evidence.
Read articleA short query to separate DNS, private access, Functions runtime and application exceptions during a private HTTP incident.
Read articleBuild an operational runbook for AKS private ingress failures by separating DNS, Application Gateway, ingress controller, Kubernetes service endpoints, pod readiness and rollback evidence.
Read articleA short query to read ingress controller and application logs together when a private AKS route returns 502, timeouts or no endpoints.
Read articleBuild an operational runbook for Azure Container Apps private ingress failures by separating DNS, ingress mode, revision routing, application logs and rollback evidence.
Read articleA short query to correlate Azure Container Apps system and console logs when private ingress, probes or revision traffic fail.
Read articleQualify a failure across Application Gateway, WAF, internal APIM and a private backend by separating DNS, routing, policy, identity and logs before any fix.
Read articleA short query to see whether a private API request is blocked by Application Gateway WAF, received by APIM or missing from the expected path.
Read articleBuild a runbook for Key Vault, Storage or private API access failures with managed identity, RBAC, private DNS, logs and real execution evidence.
Read articleA short query to separate identity denial, network path and source address when an Azure workload can no longer access Key Vault.
Read articleBuild useful synthetic probes for DNS, TLS, Application Gateway, WAF and Private Endpoint so private Azure paths fail with evidence before production incidents.
Read articleA short query to track synthetic probe failures and separate DNS, TLS, WAF or Application Gateway symptoms on an Azure private path.
Read articleApply a temporary Azure WAF custom rule with priority, KQL evidence, business validation and rollback, without permanently hiding managed-rule signals.
Read articleBuild operable rotation for secrets, certificates, and application identities with dependency inventory, evidence, change windows, monitoring, and rollback.
Read articleA short query to watch 401, 403, and 500 errors after rotating an application secret or service identity.
Read articleBuild an operational drift reading across Terraform, Private Endpoint, private DNS, CI runners, and validation evidence before a private Azure path breaks in production.
Read articleBuild useful alerts by connecting signal, diagnosis, scope, decision and rollback path instead of accumulating noisy notifications.
Read article