Forum Discussion

TheHoff70's avatar
TheHoff70
Brass Contributor
Sep 27, 2024

Mitre information missing from incident

Greetings

I have a tough time getting the MITRE parsing to work for one of my integrations. It's a security platform that's sending incidents to Sentinel using CEF and they arrive into Log Analytics looking like this, it's been truncated for clarity etc.

Now, in the analytics rule under Alert Details I've tried different settings for the tactics and/or techniques using either the mitre_id column or mitre_name but none of those ever show up in the incident.

 

Does anyone have any pointers on how to get this to work?

/Fredrik

5 Replies

  • Clive_Watson's avatar
    Clive_Watson
    Bronze Contributor

    TheHoff70 

     

    The Columns have to be in the returned data from the Alert, so the drop down will show you whats there or the Column name will error (see red text), if its missing you will have to add an Entity first

    • TheHoff70's avatar
      TheHoff70
      Brass Contributor

      Clive_Watson 

      Maybe I misunderstand your answer but my initial post show what's seen by sentinel in the alert. In the analysis rule I've tried with with the column holding the Mitre ID or the Mitre name and neither work. The respective columns are visible and selectable without error in the analytics rule.

Resources