Forum Discussion
Thijs Lecomte
Apr 09, 2020Bronze Contributor
Custom Entities
Hi all When you create a rule and configure your Entities, there used to be a line that says "More custom entities coming soon", this seems to have been removed. Can the PG share any announ...
- Apr 16, 2020
This is Ely from the product group.
Supporting more entities as part of scheduled alerts is indeed required and planned. We are working on a solution to support a more flexible way to map entities that will support more entity types and more fields for each entity.
The requirement for supporting arrays is a bit different and will require some thought.
A short-term solution can be to use the mv-expand operator to create a line for each IP address and then map them using the regular way. You can then use the Alert Grouping feature (now available in public preview) to make sure you group the alerts as to not generate too many incidents.
Ely_Abramovitch
Microsoft
Apr 16, 2020
This is Ely from the product group.
Supporting more entities as part of scheduled alerts is indeed required and planned. We are working on a solution to support a more flexible way to map entities that will support more entity types and more fields for each entity.
The requirement for supporting arrays is a bit different and will require some thought.
A short-term solution can be to use the mv-expand operator to create a line for each IP address and then map them using the regular way. You can then use the Alert Grouping feature (now available in public preview) to make sure you group the alerts as to not generate too many incidents.
akefallonitis
May 01, 2020Brass Contributor
When more custom entities is planned ? Any timeline ?
Also field aggregation in correlation should be considered in scenarios when we need to pass field as a parameter to the correlated rule especially in a MSSP enviroment or even multiple layers of correlation rules needed.
E.g Alertname , CustomerName should be able to be aggregated to be able to check which alert got hit in which Customer. Is that something that will be considered also ?
Did not find any request so i added my own in the uservoice: https://feedback.azure.com/forums/920458-azure-sentinel/suggestions/40271452-azure-sentinel-rules-fields-aggregation-and-custom
Thanks
- AMateos91Aug 24, 2023Iron Contributorakefallonitis I think you should be able these days to aggregate those user mames in order to check out the alert functionality.