Forum Discussion

Christian Bourque's avatar
Christian Bourque
Copper Contributor
May 19, 2020

SharePointFileOperation via devices with previously unseen user agents

Hi,

 

I've recently added this rule: "SharePointFileOperation via devices with previously unseen user agents" on Azure Sentinel, but when it triggers, it doesn't show essential information like the origin IP address, SharePoint directory, user agent, etc.

 

It's somewhat useless as is, is there a way to add the missing information?

 

Thanks,

 

Christian

 

  • endakelly's avatar
    endakelly
    Brass Contributor

    Christian Bourque Account and IP are defined in the query as custom entities so they should appear in the incident view. You could manually edit the query to add Site_URL as the custom entity for URL to get this information.

     

    I have a similar rule to this I've created for operations in SharePoint and I was able to define certain columns as custom entities to make them show in the incident view.

    • Christian Bourque's avatar
      Christian Bourque
      Copper Contributor

      endakellyhere's a screenshot of the last incident and as you'll see under entities, all the indicators are set to zero?!

      • GaryBushey's avatar
        GaryBushey
        Bronze Contributor

        Christian Bourque As it stands right now, this will be more of a notification that the alert was created in O365.  You should go there to get more information on it and perform the investigation.

         

        You can also check the alert that was generated to see if the information is in there and create a Logic App that can do something like add comments to incident with the information you need (although that would need to be started manually)

         

        These alerts are getting better and better as time goes on.  It may be worth entering a new request in the Azure Sentinel Customer Feedback for the information you are looking for here: https://feedback.azure.com/forums/920458-azure-sentinel

Resources