Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Port Scan Analytic Rule not Populating Entities list in Incident

Open wingcomm opened this issue 3 years ago • 5 comments

Describe the bug When the the [Port scan detected (ASIM Network Session schema)] analytic rule triggers an incident, it does not populate the SrcIPAddr columns into the Entities list with an IP address even though its configured as part of the rule. This prevents us from creating playbooks for expected behavior related to this detection.

To Reproduce Steps to reproduce the behavior:

  1. Enable the rule
  2. Ensure that ScrIPAddr is mapped to "IP Address" Screen Shot 2022-08-10 at 11 05 26 AM
  3. View incident generated by rule and see that "Entities" list is empty. Screen Shot 2022-08-10 at 11 06 17 AM
  4. Review Events to confirm the SrcIPAddr column is populating: Screen Shot 2022-08-10 at 11 06 34 AM

Expected behavior We should see all of the SrcIPAddr rows listed in the Entities field so that we can create playbooks to auto-close expected detections from certain IP Addresses.

Screenshots Included inline above.

wingcomm avatar Aug 10 '22 15:08 wingcomm

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Aug 10 '22 15:08 github-actions[bot]

Any updates on this issue?

wingcomm avatar Aug 16 '22 03:08 wingcomm

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Oct 07 '22 20:10 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Oct 07 '22 20:10 github-actions[bot]

Hi @wingcomm, kindly open a support ticket for this.

tatecksi avatar Oct 24 '22 03:10 tatecksi