azure-docs icon indicating copy to clipboard operation
azure-docs copied to clipboard

Schema for alerts not matching with documentation when sent to EventHubs and pulled via SDK/API

Open saurabh-metron opened this issue 1 year ago • 2 comments

This is regarding an issue we've encountered while exporting security alerts from Microsoft Defender for Cloud to Azure EventHub. Here are the details of the issue:

  • We are currently sending security alerts from Microsoft Defender for Cloud to Azure EventHub. However, we have noticed that the schema of these alerts does not match when we retrieve them from EventHubs using SDKs/APIs as mentioned in this doc [The alerts API]
  • Our understanding, based on this documentation, is that Defender for Cloud security alerts sent to EventHubs should adhere to the schema outlined in the alerts API documentation. Contrary to our expectations, the schema we observe from our console resembles the schema used for Log Analytics, but not exactly same.
  • To facilitate resolution, we have attached a sample log received from the EventHub for your reference.

We are uncertain whether our understanding is incorrect or if there might be a discrepancy in the documentation.

We kindly request your assistance in clarifying this matter and providing guidance on how to ensure the consistency of the schema for security alerts exported to Azure EventHub.

Also, wanted to know whether this behavior would be also true to all other customers or not

Your prompt attention to this request would be greatly appreciated image


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

saurabh-metron avatar Mar 21 '24 04:03 saurabh-metron

@saurabh-metron Thanks for your feedback! We will investigate and update as appropriate.

Naveenommi-MSFT avatar Mar 21 '24 05:03 Naveenommi-MSFT

@saurabh-metron Thanks for bringing this to our attention. I'm going to assign this to the document author so they can take a look at it accordingly.

Naveenommi-MSFT avatar Mar 25 '24 05:03 Naveenommi-MSFT

@saurabh-metron This isn't a documentation issue and requires further investigation. The best way to get help is to open a support ticket.

dcurwin avatar Apr 17 '24 18:04 dcurwin

#please-close

dcurwin avatar Apr 17 '24 18:04 dcurwin