Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Anomaly "Suspicious volume of AWS write API calls from a user account" title has a trailing space

Open ep3p opened this issue 2 years ago • 4 comments

Describe the bug In Anomalies table, the events of the rule "Suspicious volume of AWS write API calls from a user account" in the column RuleName have a trailing space.

To Reproduce Steps to reproduce the behavior:

  1. Go to a LogAnalytics workspace with the Anomalies table, and some generated events of the Anomaly rule "Suspicious volume of AWS write API calls from a user account"
  2. Run
Anomalies
| where RuleName endswith "Suspicious volume of AWS write API calls from a user account "
  1. Observe the returned events of the mentioned rule.
  2. Run
Anomalies
| where RuleName endswith "Suspicious volume of AWS write API calls from a user account"
  1. Observe the previous events do not appear.

Expected behavior The second query with no events should return events.

Screenshots image image

ep3p avatar Oct 20 '22 06:10 ep3p

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Oct 20 '22 06:10 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Oct 20 '22 06:10 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Nov 21 '22 04:11 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 10 '23 12:01 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Apr 10 '23 12:04 github-actions[bot]

Hi @ep3p are you still facing this issue, please confirm, thanks!

v-vdixit avatar May 05 '23 04:05 v-vdixit

Sorry @v-dixit I can't diagnose if this issue is still happening, because I have not received any event of this Anomaly type for a long time. The only way to know if this issue was resolved, would be to question the Anomaly team at Sentinel. This issue should be something that has happened in every Sentinel workspace.

ep3p avatar May 07 '23 18:05 ep3p

@ep3p thanks for your update we will connect with the Anomaly team and update you, thanks!

v-vdixit avatar May 29 '23 11:05 v-vdixit

Hi @ep3p we are discussing on this will update you shortly, thanks for your patience.

v-vdixit avatar Jun 09 '23 05:06 v-vdixit

Hi @ep3p we are working on this, will provide you update by end of this week, thanks!

v-vdixit avatar Jun 19 '23 07:06 v-vdixit

Hi @ep3p we are working with concerned team, will update you before end of this week, thanks!

v-vdixit avatar Jul 03 '23 07:07 v-vdixit

Hi @ep3p we are unable to find an instance where the rule name has trailing space, can you please confirm if this issue can be closed, we will keep an eye out for this error, thanks!

v-vdixit avatar Jul 10 '23 09:07 v-vdixit

@v-vdixit then we should assume this issue has been fixed by the Sentinel team, please, you could consider this issue solved and closed

ep3p avatar Jul 10 '23 09:07 ep3p

Thank you very much to everyone.

ep3p avatar Jul 10 '23 09:07 ep3p

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jul 10 '23 09:07 github-actions[bot]