Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Microsoft Exchange Security Review - Online workbook fails with "The name 'ESIEnvirnonment_s' does not refer to any known column, table or function"

Open MatthiasScharl opened this issue 1 year ago • 13 comments

Describe the bug Both the "Microsoft Exchange Security Review - Online" and "Microsoft Exchange Least Privilege with RBAC - Online" workbooks of the solution "Microsoft Exchange Security for Exchange Online" fails with "The name 'ESIEnvirnonment_s' does not refer to any known column, table or function"

image

To Reproduce Steps to reproduce the behavior: Installed the solution and setup the requierements. The runbook "Start-ESICollector" job runs without errors.

image

When I load the fuction ExchangeEnvironmentList it does not know about "ESIEnvironment_s"

image

The table ESIExchangeOnlineConfig_CL does not contain a column "ESIEnvironment_s"

image

MatthiasScharl avatar Jan 12 '24 13:01 MatthiasScharl

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 12 '24 13:01 github-actions[bot]

Hi @MatthiasScharl ,Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 18Jan24. Thanks!

v-muuppugund avatar Jan 15 '24 05:01 v-muuppugund

Hi @MatthiasScharl ,I am still working on replicating the issue as there are dependencies,so checking on it,if needed we can have a teams meeting for issue troubleshooting.

v-muuppugund avatar Jan 18 '24 16:01 v-muuppugund

[like] Matthias Scharl reacted to your message:


From: Murali Krishna Dev Uppugunduri @.> Sent: Thursday, January 18, 2024 4:01:34 PM To: Azure/Azure-Sentinel @.> Cc: Matthias Scharl @.>; Mention @.> Subject: Re: [Azure/Azure-Sentinel] Microsoft Exchange Security Review - Online workbook fails with "The name 'ESIEnvirnonment_s' does not refer to any known column, table or function" (Issue #9757)

Hi @MatthiasScharlhttps://github.com/MatthiasScharl ,I am still working on replicating the issue as there are dependencies,so checking on it,if needed we can have a teams meeting for issue troubleshooting.

— Reply to this email directly, view it on GitHubhttps://github.com/Azure/Azure-Sentinel/issues/9757#issuecomment-1898765103, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AWQ25PZQVD5MCDXJXRVMP73YPFBN5AVCNFSM6AAAAABBYE76T2VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMYTQOJYG43DKMJQGM. You are receiving this because you were mentioned.Message ID: @.***>

MatthiasScharl avatar Jan 18 '24 20:01 MatthiasScharl

Hi @MatthiasScharl ,As discussed over teams, Blocked your time tomorrow for a discussion on this issue as having queries,Please join the meeting.

v-muuppugund avatar Jan 23 '24 14:01 v-muuppugund

Hi @v-muuppugund, I did not receive any communications from you via Teams. Not sure to whom you have talked to.

MatthiasScharl avatar Jan 23 '24 15:01 MatthiasScharl

Hi @MatthiasScharl ,Apologies for the delayed response, Could you please follow the below steps

  1. Open the log Analytics work space used in automation account -->Navigate under settings->Tables->Check the Table i.e. ESIExchangeOnlineConfig_CL is Cutom table or Custom(classic),its should be custom classic table then its not editable,if its custom table we can edit column with "ESIEnvironment_s" instead of ESIEnvironment_g. 2.Please check any data in ESIExchangeOnlineConfig_CL ,I am assuming its on first run,if no data exists then delete this table and update the varaibles of Tenant with Tenant name from Microsoft Entra ID,please refer below screen shots for reference, image image

Then go Automation account ->Open Run Book->Start the job,Please refer below screen shots for reference image

After the job is successful, then the table will be created in the respective log analytics with correct column as "ESIEnvironment_s"

Please let me know if you have any issues.

We have created a bug for this issue and will be working on it https://github.com/nlepagnez/ESI-PublicContent/issues/8

v-muuppugund avatar Jan 24 '24 12:01 v-muuppugund

HI @MatthiasScharl ,Gentle Reminder,Could you please check above steps and let us know if any issues.

v-muuppugund avatar Jan 29 '24 15:01 v-muuppugund

Hello @v-muuppugund. The table ESIExchangeOnlineConfig_CL in my workspace is a Custom table (classic). I have deleted it and ran the collector again. The job completes with

image

but shows the following error

image

The table ESIExchangeOnlineConfig_CL was not re-created.

MatthiasScharl avatar Jan 30 '24 10:01 MatthiasScharl

Hi @MatthiasScharl ,maximum job stream limit is 1MB i.e. A single steam job cannot be more than 1MB,Please find below link for reference https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/azure-subscription-service-limits#automation-limits

Will investigate with detailed analysis and get back to you with an update,which command causing more size we need check,if needed we can have a teams meeting for the same.

v-muuppugund avatar Jan 31 '24 05:01 v-muuppugund

Hi @MatthiasScharl , I have verified the code, but unable to replicate the issue as don't have sufficient permissions at tenant level, Could you please share couple of time slots for a team's meeting to ([email protected])

v-muuppugund avatar Feb 02 '24 08:02 v-muuppugund

HI @MatthiasScharl ,As discussed over call,Scheduled teams meeting on monday for further trouble shooting,Please join the meeting.

v-muuppugund avatar Feb 02 '24 11:02 v-muuppugund

Hi @MatthiasScharl ,As discussed yesterday over teams meeting,able to set up local environment for debugging the run book,today will have one more session for troubleshooting the issue.

v-muuppugund avatar Feb 07 '24 02:02 v-muuppugund

Hi @MatthiasScharl ,As discussed on last Wednesday ,issue has fixed after local debugging from VS code and unable connect with you after wards,Please let me know when we can connect on next steps on this issue to check the deployed one

v-muuppugund avatar Feb 11 '24 06:02 v-muuppugund

Hi @MatthiasScharl, Hope you are doing well. Our team has waiting for your response on above comment. Thanks!

v-sudkharat avatar Feb 14 '24 11:02 v-sudkharat

Hi @MatthiasScharl ,As discussed over teams today,will be blocking your calendar on 26/2 or 27/2 at 9:30pm IST

v-muuppugund avatar Feb 16 '24 08:02 v-muuppugund

Hi @MatthiasScharl ,As discussed over team's call, the issue has been fixed, we are closing your issue (https://github.com/Azure/Azure-Sentinel/issues/9757). If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation!

v-muuppugund avatar Feb 27 '24 14:02 v-muuppugund