Queries for the CrowdStrikeCases table

For information on using these queries in the Azure portal, see Log Analytics tutorial. For the REST API, see Query.

New cases by status

Returns count of new cases by status.

CrowdStrikeCases
| where Status in ("new")
| summarize count() by Status