Forum Discussion
caitlin2250
Jul 13, 2021Copper Contributor
How to update watchlist dynamically as opposed to manually updating csv and importing it again
Hello I have a watch list that works fine but the problem I have is that each time I want to add another component to the watchlist, I have to manually update the csv file, delete the existing Watchl...
CliveWatson
Jul 13, 2021Former Employee
You can edit since last month.
https://techcommunity.microsoft.com/t5/azure-sentinel/what-s-new-azure-sentinel-update-watchlist-ui-enhancements/ba-p/2451476
https://techcommunity.microsoft.com/t5/azure-sentinel/what-s-new-azure-sentinel-update-watchlist-ui-enhancements/ba-p/2451476
- jeffazureAug 19, 2021Copper Contributor
- caitlin2250Jul 19, 2021Copper ContributorHi Clive just wanted to check if is it possible to use a domain for a watchlist column instead of FQDN. I am able to use the FQDN successfully but using the domain yields not results. Will appreciate if you could please confirm with me.
Thank you
Caitlin- JBUB_AcceleryntJul 19, 2021Brass ContributorDomain works fine for our use. We have a ARM template to deploy the watchlist as well as a playbook that works.
- CliveWatsonJul 19, 2021Former EmployeeYou create the watchlist, so you can have a column called whatever you like with whatever data you like. Ideally you'd match the column names from the Table to ones in the watchlist to make any join() easier. The two sides just need to match, and be case sensitive.
i.e if your Watchlist has a column called Domain that contains "microsoft.com" you'd be able to match to "microsoft.com" in a query.
- caitlin2250Jul 15, 2021Copper Contributorthank you very much Clive for all your help. I know from the code you provided me I am able to pull information from different departments using a Watch but I am now looking for how to achieve that in a cross workspace environment. Would that be possible?
Look forward to hearing from you soon
Caitlin