azure-data-explorer 1 Same Detection, Two Languages: Writing My Splunk Detections in KQL May 18, 2026