如何在Azure Sentinel中创建支持字段参数的全局自定义函数?
解决Kusto全局函数接收表参数报错的问题
问题原因
你通过GUI保存全局函数时,系统误将表参数识别为标量类型。Kusto全局函数的表参数需要显式声明为表类型,不能用标量或dynamic类型替代。
正确的全局函数写法(适配GUI)
如果要创建接收表参数并返回数据表的全局函数,需遵循Kusto全局函数的语法规范,直接使用.create-or-alter function语句定义:
.create-or-alter function customFunc(T: (Title: string)) { T | where Title has_any "value" | distinct Title }
双参数函数实现(结合观察列表)
针对你最终要实现的「引用观察列表并返回判定结果」的双参数函数,示例写法如下:
.create-or-alter function detectWatchlistMatch(inputTable: (Title: string, TimeGenerated: datetime), watchlistName: string) { // 加载指定观察列表 let targetWatchlist = _GetWatchlist(watchlistName); // 匹配输入表与观察列表内容,返回判定结果 inputTable | where Title has_any (targetWatchlist | project SearchKey) | extend IsMatched = true | project Title, TimeGenerated, IsMatched }
使用说明
- 在GUI中创建函数时,直接粘贴上述完整的
.create-or-alter function代码执行即可完成全局函数保存。 - 调用函数时,传入符合参数结构的表和观察列表名称:
let recentEvents = SecurityEvent | where TimeGenerated > ago(1h); detectWatchlistMatch(recentEvents, "YourWatchlistName")
内容的提问来源于stack exchange,提问作者codechallengedSINCE95
相关产品推荐
相关产品推荐

