|
| 1 | +# Azure CLI sentinel Extension # |
| 2 | +This is the extension for sentinel |
| 3 | + |
| 4 | +### How to use ### |
| 5 | +Install this extension using the below CLI command |
| 6 | +``` |
| 7 | +az extension add --name sentinel |
| 8 | +``` |
| 9 | + |
| 10 | +### Included Features ### |
| 11 | +#### sentinel alert-rule #### |
| 12 | +##### Create ##### |
| 13 | +``` |
| 14 | +az sentinel alert-rule create --etag "\\"0300bf09-0000-0000-0000-5c37296e0000\\"" \ |
| 15 | + --logic-app-resource-id "/subscriptions/d0cfe6b2-9ac0-4464-9919-dccaee2e48c0/resourceGroups/myRg/providers/Microsoft.Logic/workflows/MyAlerts" \ |
| 16 | + --trigger-uri "https://prod-31.northcentralus.logic.azure.com:443/workflows/cd3765391efd48549fd7681ded1d48d7/triggers/manual/paths/invoke?api-version=2016-10-01&sp=%2Ftriggers%2Fmanual%2Frun&sv=1.0&sig=signature" \ |
| 17 | + --action-id "912bec42-cb66-4c03-ac63-1761b6898c3e" --resource-group "myRg" \ |
| 18 | + --rule-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --workspace-name "myWorkspace" |
| 19 | +``` |
| 20 | +##### Show ##### |
| 21 | +``` |
| 22 | +az sentinel alert-rule show --resource-group "myRg" --rule-id "myFirstFusionRule" --workspace-name "myWorkspace" |
| 23 | +``` |
| 24 | +##### Show ##### |
| 25 | +``` |
| 26 | +az sentinel alert-rule show --resource-group "myRg" --rule-id "microsoftSecurityIncidentCreationRuleExample" \ |
| 27 | + --workspace-name "myWorkspace" |
| 28 | +``` |
| 29 | +##### Show ##### |
| 30 | +``` |
| 31 | +az sentinel alert-rule show --resource-group "myRg" --rule-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" \ |
| 32 | + --workspace-name "myWorkspace" |
| 33 | +``` |
| 34 | +##### List ##### |
| 35 | +``` |
| 36 | +az sentinel alert-rule list --resource-group "myRg" --workspace-name "myWorkspace" |
| 37 | +``` |
| 38 | +##### Get-action ##### |
| 39 | +``` |
| 40 | +az sentinel alert-rule get-action --action-id "912bec42-cb66-4c03-ac63-1761b6898c3e" --resource-group "myRg" \ |
| 41 | + --rule-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --workspace-name "myWorkspace" |
| 42 | +``` |
| 43 | +##### Delete ##### |
| 44 | +``` |
| 45 | +az sentinel alert-rule delete --action-id "912bec42-cb66-4c03-ac63-1761b6898c3e" --resource-group "myRg" \ |
| 46 | + --rule-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --workspace-name "myWorkspace" |
| 47 | +``` |
| 48 | +#### sentinel action #### |
| 49 | +##### List ##### |
| 50 | +``` |
| 51 | +az sentinel action list --resource-group "myRg" --rule-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" \ |
| 52 | + --workspace-name "myWorkspace" |
| 53 | +``` |
| 54 | +#### sentinel alert-rule-template #### |
| 55 | +##### List ##### |
| 56 | +``` |
| 57 | +az sentinel alert-rule-template list --resource-group "myRg" --workspace-name "myWorkspace" |
| 58 | +``` |
| 59 | +##### Show ##### |
| 60 | +``` |
| 61 | +az sentinel alert-rule-template show --alert-rule-template-id "65360bb0-8986-4ade-a89d-af3cf44d28aa" \ |
| 62 | + --resource-group "myRg" --workspace-name "myWorkspace" |
| 63 | +``` |
| 64 | +#### sentinel bookmark #### |
| 65 | +##### Create ##### |
| 66 | +``` |
| 67 | +az sentinel bookmark create --etag "\\"0300bf09-0000-0000-0000-5c37296e0000\\"" --created "2019-01-01T13:15:30Z" \ |
| 68 | + --display-name "My bookmark" --labels "Tag1" --labels "Tag2" --notes "Found a suspicious activity" \ |
| 69 | + --query "SecurityEvent | where TimeGenerated > ago(1d) and TimeGenerated < ago(2d)" \ |
| 70 | + --query-result "Security Event query result" --updated "2019-01-01T13:15:30Z" \ |
| 71 | + --bookmark-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" --workspace-name "myWorkspace" |
| 72 | +``` |
| 73 | +##### Show ##### |
| 74 | +``` |
| 75 | +az sentinel bookmark show --bookmark-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" \ |
| 76 | + --workspace-name "myWorkspace" |
| 77 | +``` |
| 78 | +##### List ##### |
| 79 | +``` |
| 80 | +az sentinel bookmark list --resource-group "myRg" --workspace-name "myWorkspace" |
| 81 | +``` |
| 82 | +##### Delete ##### |
| 83 | +``` |
| 84 | +az sentinel bookmark delete --bookmark-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" \ |
| 85 | + --workspace-name "myWorkspace" |
| 86 | +``` |
| 87 | +#### sentinel data-connector #### |
| 88 | +##### Create ##### |
| 89 | +``` |
| 90 | +az sentinel data-connector create \ |
| 91 | + --office-data-connector etag="\\"0300bf09-0000-0000-0000-5c37296e0000\\"" tenant-id="2070ecc9-b4d5-4ae4-adaa-936fa1954fa8" \ |
| 92 | + --data-connector-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" --workspace-name "myWorkspace" |
| 93 | +``` |
| 94 | +##### Show ##### |
| 95 | +``` |
| 96 | +az sentinel data-connector show --data-connector-id "763f9fa1-c2d3-4fa2-93e9-bccd4899aa12" --resource-group "myRg" \ |
| 97 | + --workspace-name "myWorkspace" |
| 98 | +``` |
| 99 | +##### Show ##### |
| 100 | +``` |
| 101 | +az sentinel data-connector show --data-connector-id "b96d014d-b5c2-4a01-9aba-a8058f629d42" --resource-group "myRg" \ |
| 102 | + --workspace-name "myWorkspace" |
| 103 | +``` |
| 104 | +##### Show ##### |
| 105 | +``` |
| 106 | +az sentinel data-connector show --data-connector-id "06b3ccb8-1384-4bcc-aec7-852f6d57161b" --resource-group "myRg" \ |
| 107 | + --workspace-name "myWorkspace" |
| 108 | +``` |
| 109 | +##### Show ##### |
| 110 | +``` |
| 111 | +az sentinel data-connector show --data-connector-id "c345bf40-8509-4ed2-b947-50cb773aaf04" --resource-group "myRg" \ |
| 112 | + --workspace-name "myWorkspace" |
| 113 | +``` |
| 114 | +##### Show ##### |
| 115 | +``` |
| 116 | +az sentinel data-connector show --data-connector-id "f0cd27d2-5f03-4c06-ba31-d2dc82dcb51d" --resource-group "myRg" \ |
| 117 | + --workspace-name "myWorkspace" |
| 118 | +``` |
| 119 | +##### Show ##### |
| 120 | +``` |
| 121 | +az sentinel data-connector show --data-connector-id "07e42cb3-e658-4e90-801c-efa0f29d3d44" --resource-group "myRg" \ |
| 122 | + --workspace-name "myWorkspace" |
| 123 | +``` |
| 124 | +##### Show ##### |
| 125 | +``` |
| 126 | +az sentinel data-connector show --data-connector-id "c345bf40-8509-4ed2-b947-50cb773aaf04" --resource-group "myRg" \ |
| 127 | + --workspace-name "myWorkspace" |
| 128 | +``` |
| 129 | +##### Show ##### |
| 130 | +``` |
| 131 | +az sentinel data-connector show --data-connector-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" \ |
| 132 | + --workspace-name "myWorkspace" |
| 133 | +``` |
| 134 | +##### List ##### |
| 135 | +``` |
| 136 | +az sentinel data-connector list --resource-group "myRg" --workspace-name "myWorkspace" |
| 137 | +``` |
| 138 | +##### Delete ##### |
| 139 | +``` |
| 140 | +az sentinel data-connector delete --data-connector-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" \ |
| 141 | + --workspace-name "myWorkspace" |
| 142 | +``` |
| 143 | +#### sentinel incident #### |
| 144 | +##### Create ##### |
| 145 | +``` |
| 146 | +az sentinel incident create --etag "\\"0300bf09-0000-0000-0000-5c37296e0000\\"" \ |
| 147 | + --description "This is a demo incident" --classification "FalsePositive" \ |
| 148 | + --classification-comment "Not a malicious activity" --classification-reason "IncorrectAlertLogic" \ |
| 149 | + --first-activity-time-utc "2019-01-01T13:00:30Z" --last-activity-time-utc "2019-01-01T13:05:30Z" \ |
| 150 | + --owner object-id="2046feea-040d-4a46-9e2b-91c2941bfa70" --severity "High" --status "Closed" --title "My incident" \ |
| 151 | + --incident-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" --workspace-name "myWorkspace" |
| 152 | +``` |
| 153 | +##### Show ##### |
| 154 | +``` |
| 155 | +az sentinel incident show --incident-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" \ |
| 156 | + --workspace-name "myWorkspace" |
| 157 | +``` |
| 158 | +##### List ##### |
| 159 | +``` |
| 160 | +az sentinel incident list --orderby "properties/createdTimeUtc desc" --top 1 --resource-group "myRg" \ |
| 161 | + --workspace-name "myWorkspace" |
| 162 | +``` |
| 163 | +##### Delete ##### |
| 164 | +``` |
| 165 | +az sentinel incident delete --incident-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" \ |
| 166 | + --workspace-name "myWorkspace" |
| 167 | +``` |
| 168 | +#### sentinel incident-comment #### |
| 169 | +##### Create ##### |
| 170 | +``` |
| 171 | +az sentinel incident-comment create --message "Some message" \ |
| 172 | + --incident-comment-id "4bb36b7b-26ff-4d1c-9cbe-0d8ab3da0014" --incident-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" \ |
| 173 | + --resource-group "myRg" --workspace-name "myWorkspace" |
| 174 | +``` |
| 175 | +##### Show ##### |
| 176 | +``` |
| 177 | +az sentinel incident-comment show --incident-comment-id "4bb36b7b-26ff-4d1c-9cbe-0d8ab3da0014" \ |
| 178 | + --incident-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" --workspace-name "myWorkspace" |
| 179 | +``` |
| 180 | +##### List ##### |
| 181 | +``` |
| 182 | +az sentinel incident-comment list --incident-id "73e01a99-5cd7-4139-a149-9f2736ff2ab5" --resource-group "myRg" \ |
| 183 | + --workspace-name "myWorkspace" |
| 184 | +``` |
0 commit comments