A SOC analyst in Microsoft Sentinel is creating a scheduled analytics rule to detect a possible password spray attack. The rule must trigger when a single source IP address has more than 10 failed logon attempts on different user accounts within a 30-minute window. The analyst writes a KQL query starting with 'SigninLogs | where ResultType == 50057' (failed logon). Which operator should the analyst use to group events by source IP and count distinct user accounts, then filter for counts above 10?
The 'summarize' operator is the correct answer because it groups rows by specified columns and applies aggregation functions such as dcount() or count() to calculate distinct user counts per IP. It produces a new table with one row per group, enabling the SOC analyst to derive meaningful metrics like unique users per IP address. Without summarize, no grouping or aggregation can be performed in KQL.
Why this answer
The `summarize` operator is required to group events by source IP address and count distinct user accounts using `dcount()` or `count()`. After summarizing, you apply a `where` clause to filter for counts above 10, which meets the rule's threshold. This is the standard pattern for aggregation in KQL.
Exam trap
The trap here is that candidates often confuse `summarize` with `extend` or `project`, thinking they can achieve aggregation without an explicit grouping operator, or they mistakenly use `where` after a simple filter instead of performing the required count and threshold check.
How to eliminate wrong answers
Option B is wrong because `where` filters rows based on conditions but cannot perform grouping or counting; it would only filter individual sign-in events, not aggregate them. Option C is wrong because `extend` adds new calculated columns to each row without any aggregation or grouping, so it cannot count distinct users per IP. Option D is wrong because `project` selects or reorders columns but does not group or count data; it would merely reduce the columns returned.