Home

Central whitelist on Azure Sentinel

%3CLINGO-SUB%20id%3D%22lingo-sub-994708%22%20slang%3D%22en-US%22%3ECentral%20whitelist%20on%20Azure%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-994708%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Experts%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20it%20possible%20to%20make%26nbsp%3Bcentral%20white-list%20for%26nbsp%3B(for%20user%2FIP)%20on%20Azure%20Sentinel%20%3F%20I%20heard%20that%20this%20feature%20will%20be%20available%20soon%2C%20but%20is%20not%20it%20available%20as%20a%20preview%20now%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-995501%22%20slang%3D%22en-US%22%3ERe%3A%20Central%20whitelist%20on%20Azure%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-995501%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F313521%22%20target%3D%22_blank%22%3E%40Jafar1970%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20by%20white%20list%20you%20mean%20a%20table%20of%20info%2C%20there%20are%20a%20few%20options%20today.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E1.%20External%20data%20(CSV%20files%20etc...)%2C%20please%20see%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcloudblogs.microsoft.com%2Findustry-blog%2Fen-gb%2Fcross-industry%2F2019%2F08%2F13%2Fazure-log-analytics-how-to-read-a-file%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fcloudblogs.microsoft.com%2Findustry-blog%2Fen-gb%2Fcross-industry%2F2019%2F08%2F13%2Fazure-log-analytics-how-to-read-a-file%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E2.%20Three%20examples%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CPRE%20class%3D%22lia-code-sample%20language-markup%22%3E%3CCODE%3E%2F%2F%0A%2F%2F%20create%20dummmy%20data%2C%20rather%20than%20use%20a%20print%20command%0A%2F%2F%0Alet%20sampleData%20%3D%20datatable(Recommendation%3Astring%2C%20Counter%3Aint)%0A%5B%0A%20%20%20%20%22My%20text%22%2C%201%2C%0A%20%20%20%20%22Some%20text%22%2C2%2C%0A%20%20%20%20%22Some%20other%20text%22%2C3%0A%5D%3B%0AsampleData%0A%7C%20where%20Recommendation%20%3D%3D%20%22Change%20the%20max%20degree%20of%20parallelism%20(MAXDOP)%20configuration%20option%20in%20Microsoft%20SQL%20Server.%22%20%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fms.portal.azure.com%23%4072f988bf-86f1-41af-91ab-2d7cd011db47%2Fblade%2FMicrosoft_Azure_Monitoring_Logs%2FDemoLogsBlade%2FresourceId%2F%252FDemo%2Fsource%2FLogsBlade.AnalyticsShareLinkToQuery%2Fq%2FH4sIAAAAAAAAA03PTUvEQAwG4PvA%25252FIeXOSlUSteb4ql6U%25252FyoN%25252FEwtlmdtZOUabq44I93urSLOYW8TyApS2vKEm0ir4RuijEe0Hn1BTx32ElgqMAjgx6v%25252FqMnzBvW9KQYfRx6us0cN8ctncFZLXGYlNLVqCnwZ4EXaiVG4kyC8Glcy8QzC6zn1rxZg1zukZ8SxTDSRbVpXAH3cIDSj%25252Ba2KhZTC6uM0jzfN2lfucI1EmlRmxVt%25252FTetkegXpQVcWvN%25252Bbc3dnlit%25252BcWQZEetYj0b8%25252FD4%25252Bb%25252F%25252FhE%25252B5NX8DPnWpNgEAAA%25253D%25253D%2Ftimespan%2FP1D%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3EGo%20to%20Log%20Analytics%20and%20Run%20Query%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CDIV%3E%0A%3CDIV%3E%3CPRE%20class%3D%22lia-code-sample%20language-markup%22%3E%3CCODE%3E%2F%2F%0A%2F%2F%20create%20dummmy%20data%2C%20and%20join%20to%20a%20real%20Table%20%0A%2F%2F%0Alet%20sampleData%20%3D%20datatable(Computer%3Astring%2C%20Recommendation%3Astring%2C%20Counter%3Aint)%0A%5B%0A%20%20%20%20%22OnPremise-12S%22%2C%20%22My%20text%22%2C%201%2C%0A%20%20%20%20%22ContosoSQLSrv1%22%2C%22Some%20text%22%2C2%2C%0A%20%20%20%20%22fake%22%2C%22Some%20other%20text%22%2C3%0A%5D%3B%0AEvent%0A%7C%20project%20Computer%20%0A%7C%20join%20sampleData%20on%20Computer%0A%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eor%2C%20shows%20countries%20that%20are%20NOT%20%22GB%22%20or%20%22US%22%20-%20just%20remove%20the%20%22!%22%20if%20you%20wanted%20the%20opposite%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CPRE%20class%3D%22lia-code-sample%20language-markup%22%3E%3CCODE%3Elet%20whiteList%20%3D%20dynamic%20(%5B'GB'%2C%20'US'%5D)%3B%20%20%2F%2F%20setup%20a%20whitelist%20of%20country%20codes%0ASigninLogs%0A%7C%20where%20TimeGenerated%20%26gt%3B%3D%20ago(1d)%0A%7C%20extend%20countryOrRegion_%20%3D%20tostring(LocationDetails.countryOrRegion)%20%0A%7C%20where%20isnotempty(countryOrRegion_)%0A%7C%20where%20countryOrRegion_%20!in%20(whiteList)%3C%2FCODE%3E%3C%2FPRE%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F155867i525B584F2F8A67BA%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%0A%3CP%3E%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%3C%2FLINGO-BODY%3E
Jafar1970
Occasional Contributor

Hi Experts

 

Is it possible to make central white-list for (for user/IP) on Azure Sentinel ? I heard that this feature will be available soon, but is not it available as a preview now?  

1 Reply

@Jafar1970 

 

If by white list you mean a table of info, there are a few options today. 

 

1. External data (CSV files etc...), please see https://cloudblogs.microsoft.com/industry-blog/en-gb/cross-industry/2019/08/13/azure-log-analytics-h...

2. Three examples 

//
// create dummmy data, rather than use a print command
//
let sampleData = datatable(Recommendation:string, Counter:int)
[
    "My text", 1,
    "Some text",2,
    "Some other text",3
];
sampleData
| where Recommendation == "Change the max degree of parallelism (MAXDOP) configuration option in Microsoft SQL Server." 

 

Go to Log Analytics and Run Query

 

//
// create dummmy data, and join to a real Table 
//
let sampleData = datatable(Computer:string, Recommendation:string, Counter:int)
[
    "OnPremise-12S", "My text", 1,
    "ContosoSQLSrv1","Some text",2,
    "fake","Some other text",3
];
Event
| project Computer 
| join sampleData on Computer

 

or, shows countries that are NOT "GB" or "US" - just remove the "!" if you wanted the opposite

let whiteList = dynamic (['GB', 'US']);  // setup a whitelist of country codes
SigninLogs
| where TimeGenerated >= ago(1d)
| extend countryOrRegion_ = tostring(LocationDetails.countryOrRegion) 
| where isnotempty(countryOrRegion_)
| where countryOrRegion_ !in (whiteList)
clipboard_image_0.png

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies