Cannot get 'Entities' via a custom analytic rule.

Yash Mudaliar 191 Reputation points Microsoft Employee
2021-05-17T06:07:38.43+00:00

Hello folks,

I am trying to write an analytic rule to get all the alerts from 'Microsoft 365 Security' center and generate incidents based on those alerts in Sentinel.

All that the rule is lacking is that I get the 'Entities' tab empty when an incident is made.

Can anybody help me out if possible with an KQL command to add/get the entities part?

Would really appreciate the help.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
{count} votes

1 answer

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,251 Reputation points Microsoft Employee
    2021-05-19T06:26:39.34+00:00

    @Yash Mudaliar In your scenario, can you use Entity mapping feature in Azure Sentinel to your analytic query.
    This enables you to add any entity based on your KQL query and utilize it to track further details.

    97726-image.png

    -----------------------------------------------------------------------------------------------------------------

    If the suggested response helped you resolve your issue, please do not forget to accept the response as Answer and "Up-Vote" for the answer that helped you for benefit of the community

    0 comments No comments