Forum Discussion
caitlin2250
Jul 13, 2021Copper Contributor
How to update watchlist dynamically as opposed to manually updating csv and importing it again
Hello I have a watch list that works fine but the problem I have is that each time I want to add another component to the watchlist, I have to manually update the csv file, delete the existing Watchl...
CliveWatson
Jul 13, 2021Former Employee
You can edit since last month.
https://techcommunity.microsoft.com/t5/azure-sentinel/what-s-new-azure-sentinel-update-watchlist-ui-enhancements/ba-p/2451476
https://techcommunity.microsoft.com/t5/azure-sentinel/what-s-new-azure-sentinel-update-watchlist-ui-enhancements/ba-p/2451476
caitlin2250
Jul 19, 2021Copper Contributor
Hi Clive just wanted to check if is it possible to use a domain for a watchlist column instead of FQDN. I am able to use the FQDN successfully but using the domain yields not results. Will appreciate if you could please confirm with me.
Thank you
Caitlin
Thank you
Caitlin
- JBUB_AcceleryntJul 19, 2021Brass ContributorDomain works fine for our use. We have a ARM template to deploy the watchlist as well as a playbook that works.
- CliveWatsonJul 19, 2021Former EmployeeYou create the watchlist, so you can have a column called whatever you like with whatever data you like. Ideally you'd match the column names from the Table to ones in the watchlist to make any join() easier. The two sides just need to match, and be case sensitive.
i.e if your Watchlist has a column called Domain that contains "microsoft.com" you'd be able to match to "microsoft.com" in a query.