Skip to content

Feature Request - Azure Sentinel - Configure entityMappings and Custom Details on Alert Rules #14078

@jstaffin-presidio

Description

@jstaffin-presidio

Azure Sentinel has added a new method for configuring Entity mappings and a method for defining custom details (key/value pairs).

This page describes the Azure Portal method for configuring the Entity Mappings on an alert rule
https://docs.microsoft.com/en-us/azure/sentinel/map-data-fields-to-entities

This page describes the Azure Portal method for configuring the custom details key/value Paris on an alert rule
https://docs.microsoft.com/en-us/azure/sentinel/surface-custom-details-in-alerts

Neither the current GA nor the preview REST or SDK for go support configuring these elements on an alert rule.

At the moment all other aspects of our sentinel deployment are automated except for this capability. We require the ability to map these values to surface required context on the generated alert for use in our SOAR workflows. We currently deploy rules using an automated method and require Azure Portal manual configuration to perform the remaining entity mapping and custom details configuration.

Metadata

Metadata

Assignees

No one assigned

    Labels

    SentinelService AttentionWorkflow: This issue is responsible by Azure service team.questionThe issue doesn't require a change to the product in order to be resolved. Most issues start as that

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions