I want to collect logs and analyze them, so I'm getting ready
Microsoft is planning to use kql
For example, users recorded 50 logs a day
How should I use it when I want to have the largest or most recent value?
There are multiple query values for one user, but I want to leave only one unique value
I can't find out even if I look up the document, so I ask you a question