Microsoft Sentinel
Cloud and workloads

Watchlists Queries

In brief

The page date and custom metadata were updated, and the example query text now uses clearer wording for the Log Analytics screenshot and guidance on creating custom analytics rules with watchlists.

What Defender admins need to know

No administrator action is required; the revised text provides clearer documentation for using watchlists in queries and analytics rules.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

 on $left.RemoteIPCountry == $right.SearchKey
```

The following image shows the results of this example query appear in Log Analytics.Analytics as shown in the following screenshot.

:::image type="content" source="./media/watchlists-queries/sentinel-watchlist-queries-join.png" alt-text="Screenshot of queries against watchlist as lookup." lightbox="./media/watchlists-queries/sentinel-watchlist-queries-join.png":::
  1. Complete the rest of the tabs in the Analytics rule wizard.

Watchlists are refreshed in your workspace every 12 days, updating the TimeGenerated field. For more information,information about creating custom analytics rules that use watchlists, see Create custom analytics rules to detect threats.

View the list of watchlist aliases