Jun 01 2022 02:56 AM - edited Jun 01 2022 03:00 AM
Hi everyone,
I'm trying to create a workbook that will list analytics rules that haven't triggered any alerts/incidents in specified time range (e.g. in last 7 days). First step is to prepare a KQL query, and as there is no rules table (list of rules is only available through REST API) my idea is:
I've looked at "Security Operations Efficiency" and "Analytics Efficiency" workbooks but they don't cover this requirement.
Has anyone done something similar, is there a better way to get the data (without Logic App and watchlist)?
Thanks,
Bojan
Jun 01 2022 03:44 AM
SolutionJun 01 2022 03:55 AM
@Clive_Watson I agree. Select one or more of the rules that are listed and then scroll down to the bottom of the page and look at the "Rules that require attention". This will tell you if the rule has created an alert within in the selected timespan.
Unfortunately, there does not appear to be any way to select all the rules at one time but at the very least it will tell you the query that it uses to determine if the rule has kicked off an alert or not and you can go from there.
Jun 01 2022 03:57 AM
Jun 01 2022 04:03 AM
Jun 01 2022 06:20 AM
Jun 01 2022 06:35 AM