Forum Discussion

wowbagger's avatar
wowbagger
Copper Contributor
Feb 20, 2023
Solved

Sentinel Watchlist stuck in queued state for days...

Dear Members,

 

I recently read https://cryptsus.com/blog/enrich-geolocation-sentinel-siem.html how on how to do geolocation of IPv4 addresses in Sentinel efficiently.

The Azure API with the 100 addresses/user/day rate limit simply does not cut it.

Just as the article recommended, I uploaded the merged csv file as an Azure blob, and created the watchlist. Now the watchlist has been sitting in Queued state for 4 days, and apparently nothing is happening (no data has been loaded to it from the csv file). There are no other visible tasks running in parallel, and I can't even delete the watchlist, as no data has been downloaded to it.

In the past I had a watchlist that I deleted, but even that took 8 hours to download, and then 8 hours to delete. Far from ideal...

Is there anything I can do about this? Or is this a known behavior for watchlists in Sentinel? Or should I try to contact Support?

 

Thanks,

János

  • sedohr's avatar
    sedohr
    Mar 29, 2023
    Hi there,
    I spoke with Microsoft support who cleared the queued watchlists in a few different workspaces. They confirmed that there was no option for me to do this from the Azure Portal and if it happens again to just contact them to fix.
    Bit of an odd one.

10 Replies

Resources