question

PeterAAlvarado-6599 avatar image
0 Votes"
PeterAAlvarado-6599 asked saldana-msft edited

Error in Azure Sysmon Workbook project' operator: Failed to resolve table or column expression named 'process_create_whitelist

Hello everyone. I have been trying to set up a lab on my Azure Sentinel tenant to receive sysmon logs. I have followed some of the tutorials posted using the agents. Everything seem to work fine

I am receiving logs from sysmon to azure, but where I am having problems is with the Sysmon Workbook.

I get the error below, and nothing is being rendered. Has anyone run into this before?

'project' operator: Failed to resolve table or column expression named 'process_create_whitelist'
If issue persists, please open a support ticket. Request id:

187094-screenshot-2022-03-25-203223.png


187103-sent1.png


azure-monitormicrosoft-sentinelwindows-sysinternals-sysmonmicrosoft-graph-workbooks
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AndrewBlumhardt-1137 avatar image
0 Votes"
AndrewBlumhardt-1137 answered AndrewBlumhardt-1137 edited

There seems to be something missing here. The first tab has queries based on several undefined data sources; possibly parser functions. The workbook is possibly outdated and lacking full instructions. You might reach out to the author Eduardo listed in the opening comments.

Correction, The workbook description includes the following link describing the parser. https://github.com/BlueTeamLabs/sentinel-attack/wiki/Onboarding-sysmon-data-to-Azure-Sentinel

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

PeterAAlvarado-6599 avatar image
0 Votes"
PeterAAlvarado-6599 answered

So you think this might be a parsing issue?

Thank you for your recommendations, I will surely try those.

I took a snapshot of the complete errors from the Workbook Sysmon Threat Hunting.

Again thank you.

187066-screenshot-2022-03-26-021215.png



5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AndrewBlumhardt-1137 avatar image
0 Votes"
AndrewBlumhardt-1137 answered PeterAAlvarado-6599 commented

Those let statements are attempting to create stored lists by calling functions (stored KQL queries). At least I think those are functions. I assumed Step #9 in the instructions would address this missing requirement. I think the author may be the only person that can clear this up.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

I'm still working on the solution you sent me, I have not had the time to.

0 Votes 0 ·