ELDK27 starts in DAYS HOURS MINUTES SECONDS Visit event site → (opens in a new tab)
Experts Live Denmark

What’s in Your Logs? - Expert Edition

Experts Live Denmark 2027
← All sessions
Technical Session 60 min Room A1 Keynote-Floor 0-Max 1500 Security Black Belt (500) Security Microsoft Defender for Endpoint Microsoft Defender for Identity Microsoft Sentinel Microsoft Graph

Wednesday 10 February 2027, 11:30–12:30

Speakers

  • Bert-Jan Pals

About this session

Threat hunters, Detection Engineers, SOC/IR analysts and other security specialists all depend on logs. Yet one of the biggest challenges in remains surprisingly fundamental: Do you actually know what is in your logs? Most security teams know which data sources they have onboarded. They know the tables, schemas, and products. But knowing that a log source exists is not the same as understanding the full security value hidden within it. This Level 500 Black Belt session goes beyond the traditional discussion of log sources and telemetry. We will explore using demo's how to systematically discover, validate, classify, and operationalize the data available in your environment. After this session, attendees will have: - A repeatable methodology for exploring unfamiliar log sources. - Techniques for discovering security-relevant telemetry hidden in existing data. - Azure native automation for log content and schema discovery. - Practical ways to connect log discovery with threat hunting and detection engineering. Audience: Experienced threat hunters, detection engineers, SOC analysts, incident responders, security architects, automation specialists and everyone who wants to get more value out of their logs