Sentinel Analytic rules still show up in SentinelHealth despite being deleted

Andreas Bjelven 135 Reputation points
2024-01-22T15:12:04.2933333+00:00

Hi,

I am currently trying to learn Sentinel through my lab tenant. I've managed to connect some data connectors and data is coming in to my Sentinel environment.

Now, I've started to mess around with the analytic rules. I've created a few and enabled them. Some of them triggered alerts and generated incidents and others did not (I have to look at the KQL). My question is, I deleted some rules and they've disappeared from my analytic rule page.

However, when I go to the dashboard of my Sentinel, I can see that there is "a lot" of data that comes in from SentinelHealth:
User's image

When I check the SentinelHealth logs, I can see that the analytic rules that I have deleted are still running...
User's image

Is there something else I need to do? I Maybe wait for a "sync" or something?

//Andreas Bjelvén

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Accepted answer
  1. Akshay-MSFT 17,956 Reputation points Microsoft Employee Moderator
    2024-01-23T09:31:14.4433333+00:00

    @Andreas Bjelven

    Thank you for posting your query on Microsoft Q&A, from above description I could understand that you have created sentinel analytics rules, got events triggered and later deleted the rule however the events are showing up in dashboard and audit details of the sentinel health.

    Please do correct me by responding in the comments for any discrepancies.

    Sentinel dashboard does hold the data for past 24 hours to 30 days. Any events generated by the rules before deletion may show up within the dashboard as the events have been saved in the workspace.

    User's image

    • Same goes with SentinelHealth and SentinelAudit data tables:

    The following types of analytics rule health events are logged in the SentinelHealth table:

    The following types of analytics rule audit events are logged in the SentinelAudit table:

    The screenshot you have shared have the deleted log of the rule, so it would show up but there won't be any new events generated:

    User's image

    ---Please "Accept the answer (Yes)" and "share your feedback ". This will help us and others in the community as well.

    Thanks, Akshay Kaushik

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.