You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置Azure Sentinel DCR时遇400 InvalidPayload错误求助

问题描述

使用Terraform配置Microsoft Sentinel与VM的连接时,已成功部署Log Analytics Workspace、Sentinel及VM扩展,但创建Data Collection Rule(DCR)时持续返回400错误,提示InvalidPayload: Data collection rule is invalid。

错误信息

Error: creating Data Collection Rule (Subscription: "28a9287a-502c-4b96-aea4-34779d8ca1b4"
│ Resource Group Name: "sentinel-lab"
│ Data Collection Rule Name: "sentinel-dcr"): unexpected status 400 (400 Bad Request) with error: InvalidPayload: Data collection rule is invalid  
│
│   with azurerm_monitor_data_collection_rule.sentinel-dcr,
│   on sentinel.tf line 33, in resource "azurerm_monitor_data_collection_rule" "sentinel-dcr":
│   33: resource "azurerm_monitor_data_collection_rule" "sentinel-dcr" {
│
│ creating Data Collection Rule (Subscription: "28a9287a-502c-4b96-aea4-34779d8ca1b4"
│ Resource Group Name: "sentinel-lab"
│ Data Collection Rule Name: "sentinel-dcr"): unexpected status 400 (400 Bad Request) with error: InvalidPayload: Data collection rule is invalid 

现有Terraform代码

#Create Log Analytics Workspace

resource "azurerm_log_analytics_workspace" "sentinel-log" {
  name                = "sentinel-log"
  location            = azurerm_resource_group.sentinel-lab.location
  resource_group_name = azurerm_resource_group.sentinel-lab.name
  sku                 = "PerGB2018"
  retention_in_days   = 30
}

# Enable Microsoft Sentinel by adding the SecurityInsights solution
resource "azurerm_log_analytics_solution" "sentinel" {
  solution_name         = "SecurityInsights"
  location              = azurerm_resource_group.sentinel-lab.location
  resource_group_name   = azurerm_resource_group.sentinel-lab.name
  workspace_name        = azurerm_log_analytics_workspace.sentinel-log.name

  plan {
    publisher = "Microsoft"
    product   = "OMSGallery/SecurityInsights"
  }

  workspace_resource_id = azurerm_log_analytics_workspace.sentinel-log.id
}

# Data Collection Rule on AMA
resource "azurerm_monitor_data_collection_rule" "sentinel-dcr" {
  name                = "sentinel-dcr"
  location            = azurerm_resource_group.sentinel-lab.location
  resource_group_name = azurerm_resource_group.sentinel-lab.name

  data_sources {
    windows_event_log {
      name = "Windows-Log"
      x_path_queries = ["*![System/Level=1]"]  # Optional filtering
      streams        = ["Application", "System", "Security"]
    }
  }

  destinations {
    log_analytics {
      name                  = "log-analytics"
      workspace_resource_id = azurerm_log_analytics_workspace.sentinel-log.id
    }
  }

  data_flow {
    streams      = ["Microsoft-InsightsMetrics"]
    destinations = ["log-analytics"]
  }
}

# Associate DCR with the Windows VM
resource "azurerm_monitor_data_collection_rule_association" "sentinel-dcr-association" {
  name                    = "sentinel-dcr-association"
  target_resource_id      = azurerm_windows_virtual_machine.sentinel-vm.id
  data_collection_rule_id = azurerm_monitor_data_collection_rule.sentinel-dcr.id
}

# Extension
resource "azurerm_virtual_machine_extension" "sentinel-ama" {
  name                       = "AzureMonitorWindowsAgent"
  virtual_machine_id         = azurerm_windows_virtual_machine.sentinel-vm.id
  publisher                  = "Microsoft.Azure.Monitor"
  type                       = "AzureMonitorWindowsAgent"
  type_handler_version       = "1.0"
  auto_upgrade_minor_version = true
}
问题排查与修复方案

你的DCR配置存在两处关键错误,导致Payload无效:

  1. 数据源与数据流的Stream不匹配

    • windows_event_log数据源的streams参数需使用固定标识["Microsoft-WindowsEventLog"],而非直接填写日志类别(Application/System/Security),日志类别应在x_path_queries中指定。
    • 当前data_flow中使用的Microsoft-InsightsMetrics是指标数据的Stream,与Windows事件日志的Stream不匹配,导致数据流无法关联到正确的数据源。
  2. XPath查询格式错误

    • 原*![System/Level=1]不符合Windows事件日志XPath标准格式,正确的排除信息级(Level=1)日志的XPath应为*[System/Level != 1],且需为每个日志类别单独指定查询规则。

修正后的DCR代码

resource "azurerm_monitor_data_collection_rule" "sentinel-dcr" {
  name                = "sentinel-dcr"
  location            = azurerm_resource_group.sentinel-lab.location
  resource_group_name = azurerm_resource_group.sentinel-lab.name

  data_sources {
    windows_event_log {
      name = "Windows-Log"
      # 修正XPath查询格式,为每个日志类别单独设置过滤规则
      x_path_queries = [
        "Application[System/Level != 1]",
        "System[System/Level != 1]",
        "Security[System/Level != 1]"
      ]
      # 使用Windows事件日志的标准Stream标识
      streams        = ["Microsoft-WindowsEventLog"]
    }
  }

  destinations {
    log_analytics {
      name                  = "log-analytics"
      workspace_resource_id = azurerm_log_analytics_workspace.sentinel-log.id
    }
  }

  data_flow {
    # 数据流关联Windows事件日志的Stream
    streams      = ["Microsoft-WindowsEventLog"]
    destinations = ["log-analytics"]
  }
}

额外说明

  • 若需同时收集VM指标数据,需新增performance_counter数据源,并添加对应Microsoft-InsightsMetrics的数据流规则。
  • 你的Azure Monitor Agent(AMA)扩展配置正确,可保留原代码。

内容的提问来源于stack exchange,提问作者Samuel Lee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 01:14:56