Azure-Sentinel
Azure-Sentinel copied to clipboard
Query: Entra ID Local Device Join Information and Transport Key Registry Keys Access
Describe the bug Query fails to run as a Sentinel Hunting Query or a Sentinel Analytics. The query does work in Log Analytics Workspace
To Reproduce Steps to reproduce the behavior:
- Go to 'Sentinel click on Analytics
- Click on 'create schedle alert'
- Scroll down to 'add query to query section
- Server Error, view query results works fine, but cannot save alert rule
Expected behavior Rule should save, query should function
Screenshots If applicable, add screenshots to help explain your problem.
The server encountered a temporary error and could not complete your request.
Desktop (please complete the following information):
- OS: [e.g. iOS] Windows 10
- Browser [e.g. chrome, safari] Edge
- Version [e.g. 22]
Smartphone (please complete the following information):
- Device: [e.g. iPhone6]
- OS: [e.g. iOS8.1]
- Browser [e.g. stock browser, safari]
- Version [e.g. 22]
Additional context Azure Gov Environment
Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.
Hi @rogfleming ,Could you please share more details with screen shot,Which solution,Which query you are facing the issue?
Hi @rogfleming, Gentle Reminder: We are waiting for your response on this issue. If you still need to keep this issue active, please respond to it in the next 2 days. If we don't receive a response by 13-02-2023 date, we will be closing this issue. Thanks!
ince we have not received a response in the last 5 days, we are closing your issue (https://github.com/Azure/Azure-Sentinel/issues/9874) as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation!