Forum Discussion

PhilippeAugras's avatar
PhilippeAugras
Brass Contributor
Mar 22, 2021
Solved

Sentinel automation - create Analytics alert rules from Alert rule templates using PowerShell

Hi,

 

I regularly deploy Sentinel to several clients as part of Security Workshops and every time, I spend a lot of time enabling scheduled analytic rules related to the deployed connectors. I'd like to use PowerShell and I found the AzSentinel module today. I can use it to create a scheduled analytic rule but even if I give a template name, I still have to provide severity, trigger and so on. I  wanna use default values from the template.

I thought about exporting those rules from an already existing Sentinel environment but if the Sentinel template changes, my export becomes worthless for new clients. 

Does anyone have an idea about how to do that ? I mean, being able to create a scheduled analytic rule from a template name by only providing a new alert rule should be something easy, right ?

Regards,

 

P. Augras

Resources