Share via

Sentinel Watchlist Different when going to Create

CTS 55 Reputation points
2023-10-22T17:17:05.0666667+00:00

I'm creating a lab for a course I'm doing, I'm trying to create a Watchlist in Sentinel and when in the Source section after Browsing for my file I select the Search Key network then go to Review + Create and the Search key is different to what I chose1.PNG2.PNG

Microsoft Security | Microsoft Sentinel
0 comments No comments

Answer accepted by question author

  1. JamesTran-MSFT 37,251 Reputation points Microsoft Employee Moderator
    2023-10-26T19:42:25.9933333+00:00

    @CTS

    Thank you for your post and I apologize for the delayed response!

    When creating my own Watchlist in Microsoft Sentinel based off your screenshots, I was able to reproduce your issue. However, after creating the Watchlist you'll be able to confirm that the Search Key you selected is correct by:

    1. Navigating to the Watchlist and selecting View in Logs. Note: I had to select another tab within Sentinel and go back to my Watchlists to see this option.
    2. After you select View in Logs the query should automatically run.
    3. The example below shows the results of the extraction of the network and latitude fields. The SearchKey is shown as its own column and in this case as the network addresses.

    User's image

    Additional Links:

    I hope this helps!

    If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.

    Was this answer helpful?

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.