SOLVED

Sentinel Watchlist and KQL query

%3CLINGO-SUB%20id%3D%22lingo-sub-2817260%22%20slang%3D%22en-US%22%3ESentinel%20Watchlist%20and%20KQL%20query%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2817260%22%20slang%3D%22en-US%22%3E%3CP%3EI%20created%20a%20Sentinel%20VIP%20user%20watchlist%20and%20would%20like%20to%20use%20the%20SecurityAlert%20logs%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20the%20following%20query%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-applescript%22%3E%3CCODE%3ESecurityAlert%0A%7C%20extend%20User_Account_%20%3D%20tostring(parse_json(ExtendedProperties).%5B%22User%20Account%22%5D)%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20VIP%20user%20watchlist%20uses%26nbsp%3BUser%20Principal%20Name%20as%20a%20field%20so%20how%20can%20I%20create%20an%20alias%20for%20the%20User_Account%20field%20to%20match%20the%26nbsp%3BUser%20Principal%20Name%20of%20the%20User%20VIP%20watchlist%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThx%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2818699%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Watchlist%20and%20KQL%20query%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2818699%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F173036%22%20target%3D%22_blank%22%3E%40Jeff%20Walzer%3C%2FA%3E%26nbsp%3BIs%20there%20any%20reason%20you%20cannot%20just%20change%20the%20extend%20in%20line%202%20to%20use%20the%20User%20Principal%20Name%20like%3A%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-applescript%22%3E%3CCODE%3E%7C%20extend%20%5B'User%20Principal%20Name'%5D%20%3D%20tostring(parse_json(ExtendedProperties).%5B%22User%20Account%22%5D)%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20need%20to%20keep%20that%20User_Account%20variable%20you%20can%20do%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-applescript%22%3E%3CCODE%3E%7C%20extend%20%5B'User%20Principal%20Name'%5D%20%3D%20User_Account%3C%2FCODE%3E%3C%2FPRE%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2822551%22%20slang%3D%22en-US%22%3ERe%3A%20Sentinel%20Watchlist%20and%20KQL%20query%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2822551%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46875%22%20target%3D%22_blank%22%3E%40Gary%20Bushey%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20went%20back%20to%20the%20Watchlist%20documentation%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fwatchlists%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fwatchlists%3C%2FA%3E)%20and%20saw%20this%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22JeffWalzer_0-1633616884367.png%22%20style%3D%22width%3A%20566px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F315896iA19AD295172569EA%2Fimage-dimensions%2F566x75%3Fv%3Dv2%22%20width%3D%22566%22%20height%3D%2275%22%20role%3D%22button%22%20title%3D%22JeffWalzer_0-1633616884367.png%22%20alt%3D%22JeffWalzer_0-1633616884367.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20that%2C%20I%20went%20back%20and%20rewrote%20the%20query%20to%20as%20follows%3A%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-applescript%22%3E%3CCODE%3ESecurityAlert%0A%7C%20lookup%20kind%3Dleftouter%20_GetWatchlist('VIP')%20%0Aon%20%24left.CompromisedEntity%20%3D%3D%20%24right.SearchKey%0A%7C%20project%20TimeGenerated%2C%20CompromisedEntity%2C%20AlertName%2C%20AlertSeverity%2C%20Description%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eand%20I'm%20still%20seeing%20the%20same%20issue%20in%20which%20I%20see%20users%20who%20aren't%20on%20the%20VIP%20list%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

I created a Sentinel VIP user watchlist and would like to use the SecurityAlert logs

 

I have the following query:

 

SecurityAlert
| extend User_Account_ = tostring(parse_json(ExtendedProperties).["User Account"])

 

 

The VIP user watchlist uses User Principal Name as a field so how can I create an alias for the User_Account field to match the User Principal Name of the User VIP watchlist?

 

Thx 

5 Replies
best response confirmed by Jeff Walzer (Contributor)
Solution

@Jeff Walzer Is there any reason you cannot just change the extend in line 2 to use the User Principal Name like:

| extend ['User Principal Name'] = tostring(parse_json(ExtendedProperties).["User Account"])

 

If you need to keep that User_Account variable you can do

| extend ['User Principal Name'] = User_Account

@Gary Bushey - thx for the rely

 

So I now have the following query:

 

let watchlist = (_GetWatchlist('VIP') | project 'User Principal Name');
SecurityAlert
| extend ['User Principal Name'] = tostring(parse_json(ExtendedProperties).["User Account"])
| where 'User Principal Name' in (watchlist)
| project TimeGenerated, ['User Principal Name']

But when I run the query, I still see user names that aren't part of the VIP list

 

Thx 

@Gary Bushey 

 

I went back to the Watchlist documentation (https://docs.microsoft.com/en-us/azure/sentinel/watchlists) and saw this:

 

JeffWalzer_0-1633616884367.png

 

With that, I went back and rewrote the query to as follows:

SecurityAlert
| lookup kind=leftouter _GetWatchlist('VIP') 
on $left.CompromisedEntity == $right.SearchKey
| project TimeGenerated, CompromisedEntity, AlertName, AlertSeverity, Description

 

and I'm still seeing the same issue in which I see users who aren't on the VIP list

I think you want to use inner rather than leftouter. From the KQL Documentation page: leftouter is used, which means all those rows will appear in the output with null values used for the missing values of RightTable columns added by the operator.

While inner will omit the rows

@Gary Bushey 

 

Thx again for the reply.

 

I used this statement to alias User_Acccount_ to "User Account"

| extend User_Account_ = tostring(parse_json(ExtendedProperties).["User Account"])

 

and my final working KQL queries look like this:

let watchlist = (_GetWatchlist('VIP') | project 'User Principal Name');
SecurityAlert
| extend User_Account_ = tostring(parse_json(ExtendedProperties).["User Account"])
| where 'User Principal Name' in (watchlist)

and

//Watchlist as a variable
let watchlist = (_GetWatchlist('VIP') | project 'User Principal Name');
SigninLogs
| where 'User Principal Name' in (watchlist)
| where isnotempty(ResultDescription)
| project TimeGenerated, UserPrincipalName, ResultDescription, Identity, Location, AppDisplayName