Azure / Azure/azure-rest-api-specs
Feature Request - Azure Sentinel - Configure entityMappings and Custom Details on Alert Rules
- Dominant language
- TypeSpec
- Stars
- 3.1k
- Forks
- 5.9k
- Avg merge
- 2d 22h
- Merged PRs (30d)
- 444
Description
Azure Sentinel has added a new method for configuring Entity mappings and a method for defining custom details (key/value pairs).
This page describes the Azure Portal method for configuring the Entity Mappings on an alert rule
https://docs.microsoft.com/en-us/azure/sentinel/map-data-fields-to-entities
This page describes the Azure Portal method for configuring the custom details key/value Paris on an alert rule
https://docs.microsoft.com/en-us/azure/sentinel/surface-custom-details-in-alerts
Neither the current GA nor the preview REST or SDK for go support configuring these elements on an alert rule.
At the moment all other aspects of our sentinel deployment are automated except for this capability. We require the ability to map these values to surface required context on the generated alert for use in our SOAR workflows. We currently deploy rules using an automated method and require Azure Portal manual configuration to perform the remaining entity mapping and custom details configuration.
Contributor guide
Research direction
The issue concerns Azure Sentinel alert rules and links documentation for entity mappings and custom details. Start by locating the Azure Sentinel alert-rule REST specification and compare its schema with those documented capabilities. Done means both configurations are represented for automated deployment, with the relevant specification checks passing.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, go
- Domain
- api, cloud
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100