You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure Sentinel中创建支持字段参数的全局自定义函数?

解决Kusto全局函数接收表参数报错的问题

问题原因

你通过GUI保存全局函数时,系统误将表参数识别为标量类型。Kusto全局函数的表参数需要显式声明为表类型,不能用标量或dynamic类型替代。

正确的全局函数写法(适配GUI)

如果要创建接收表参数并返回数据表的全局函数,需遵循Kusto全局函数的语法规范,直接使用.create-or-alter function语句定义:

.create-or-alter function customFunc(T: (Title: string))
{
    T | where Title has_any "value"
      | distinct Title
}

双参数函数实现(结合观察列表)

针对你最终要实现的「引用观察列表并返回判定结果」的双参数函数,示例写法如下:

.create-or-alter function detectWatchlistMatch(inputTable: (Title: string, TimeGenerated: datetime), watchlistName: string)
{
    // 加载指定观察列表
    let targetWatchlist = _GetWatchlist(watchlistName);
    // 匹配输入表与观察列表内容,返回判定结果
    inputTable 
    | where Title has_any (targetWatchlist | project SearchKey)
    | extend IsMatched = true
    | project Title, TimeGenerated, IsMatched
}

使用说明

  • 在GUI中创建函数时,直接粘贴上述完整的.create-or-alter function代码执行即可完成全局函数保存。
  • 调用函数时,传入符合参数结构的表和观察列表名称:
let recentEvents = SecurityEvent | where TimeGenerated > ago(1h);
detectWatchlistMatch(recentEvents, "YourWatchlistName")

内容的提问来源于stack exchange,提问作者codechallengedSINCE95

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 20:43:17