CloudAppEvents
| where ActionType == 'DefenseEvasion'
| extend
AlertUri = parse_json(RawEventData).AlertUri,
AlertDisplayName = parse_json(RawEventData).AlertDisplayName,
AlertSeverity = parse_json(RawEventData).AlertSeverity
| project AlertUri, AlertDisplayName, AlertSeverity
CloudAppEvents
| where ActionType == 'DefenseEvasion'
| extend
AlertUri = parse_json(RawEventData).AlertUri,
AlertDisplayName = parse_json(RawEventData).AlertDisplayName,
AlertSeverity = parse_json(RawEventData).AlertSeverity
| project AlertUri, AlertDisplayName, AlertSeverity