Working with time in KQL
ago
syntax
where TimeGenerated [operator] ago([number][d=days, m=minutes, s=seconds])FileCreationEvents
| where TimeGenerated > ago(1d)FileCreationEvents
| where TimeGenerated < ago(1d)between
syntax:
Example
now
Syntax
Example
Last updated

