Azure-Sentinel
Azure-Sentinel copied to clipboard
Sysmon Parser - 'extend' operator: Failed to resolve scalar expression named '["@Name"]'.
Describe the bug Using the Sysmon Parser(https://github.com/Azure/Azure-Sentinel/blob/master/Parsers/Sysmon/Sysmon-AllVersions_Parser.txt) to create an analytics rule. You are presented with the error: 'extend' operator: Failed to resolve scalar expression named '["@Name"]'.
To Reproduce Steps to reproduce the behavior:
- Create the following query in Azure Sentinel as an scheduled analytics rule:
- This will present the error.
Expected behavior No error should occur.
Screenshots
Desktop (please complete the following information):
- OS: Windows 10
- Browser Firefox
- Version 102.0
Additional context Add any other context about the problem here.
Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.
Just to link a similar issue I found raised last year: https://github.com/Azure/Azure-Sentinel/issues/2200
Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.
We are still seeing this problem any plans to resolve?
@WoodellJ : We merged the PR Could you please let us know still you are facing the issue ?
@WoodellJ : We merged the PR Could you please let us know still you are facing the issue or issue got resolved ?
Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.
Hi @WoodellJ,
We are closing this issue as its already addressed and we are not seeing this issue anymore. Please find the below screenshot for your reference. Please feel free to reopen if you need any further assistance on this.
Thanks
Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.
Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.