Queries for the CrowdStrikeIncidents table

For information on using these queries in the Azure portal, see Log Analytics tutorial. For the REST API, see Query.

Open incidents by state

Returns count of open and in-progress incidents by state.

CrowdStrikeIncidents
| where Status in ("open", "in_progress")
| summarize count() by State