Is it possible to manipulate Azure Sentinel Watchlists through Powershell/API

Geoffrey Montel 1 Reputation point
2021-08-18T14:06:27.427+00:00

Hi team:
Is it possible to administrate Azure Sentinel Watchlists through Powershell, like Rules with Az.SecurityInsights?

Aim is to keep Watchlist references in outer VCS for simpler manipulation, and sync it with Powershell to remote.

Thanks,

Windows Server PowerShell
Windows Server PowerShell
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.PowerShell: A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
5,580 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,189 questions
{count} votes

1 answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,661 Reputation points Microsoft Employee
    2021-08-19T21:45:03.517+00:00

    @Geoffrey Montel
    Thank you for your post!

    As of right now, using the Log Analytics’ REST API to manage watchlists, you can only create, modify, and delete watchlists and their items using the REST API - Manage watchlists in Azure Sentinel using REST API. If you'd like the ability to administer Azure Sentinel Watchlists using REST APIs, I'd recommend leveraging the Azure Sentinel GitHub repo to create a feature request for our engineering team.

    Additional Links:
    Azure Sentinel REST APIs
    Azure Sentinel Tech Community

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.