You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过ARM模板(PowerShell执行)将工作簿部署至Microsoft Sentinel工作簿库?

将工作簿通过ARM模板部署到Microsoft Sentinel工作簿库的解决方案

要把工作簿部署到Microsoft Sentinel工作簿库而非Azure Monitor库,核心是修改ARM模板中的galleries配置和工作簿关联范围,具体操作如下:

关键ARM模板修改点

  1. 调整galleries字段配置
    替换原模板中galleries数组内的参数,将工作簿归类到Sentinel专属库:

    "galleries": [
      {
        "name": "Sentinel",
        "category": "Workbooks",
        "resourceType": "Microsoft.SecurityInsights/workspaces",
        "galleryType": "shared"
      }
    ]
    
  2. 绑定Sentinel工作区
    在工作簿的properties中添加scope字段,指向目标Sentinel工作区的资源ID,确保工作簿与指定Sentinel实例关联:

    "scope": "[resourceId('Microsoft.SecurityInsights/workspaces', parameters('sentinelWorkspaceName'))]"
    
  3. 匹配地理位置
    确保工作簿的location参数与Sentinel工作区的地理位置完全一致,避免部署时出现区域不匹配错误。

完整ARM模板示例片段

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workbookName": {
      "type": "string",
      "defaultValue": "Sentinel-Workbook-Demo"
    },
    "workbookDisplayName": {
      "type": "string",
      "defaultValue": "Sentinel Threat Analytics Workbook"
    },
    "sentinelWorkspaceName": {
      "type": "string"
    },
    "location": {
      "type": "string"
    },
    "workbookSerializedData": {
      "type": "string"
    }
  },
  "resources": [
    {
      "type": "Microsoft.Insights/workbooks",
      "apiVersion": "2021-08-01",
      "name": "[parameters('workbookName')]",
      "location": "[parameters('location')]",
      "kind": "shared",
      "properties": {
        "displayName": "[parameters('workbookDisplayName')]",
        "serializedData": "[parameters('workbookSerializedData')]",
        "version": "1.0",
        "galleries": [
          {
            "name": "Sentinel",
            "category": "Workbooks",
            "resourceType": "Microsoft.SecurityInsights/workspaces",
            "galleryType": "shared"
          }
        ],
        "scope": "[resourceId('Microsoft.SecurityInsights/workspaces', parameters('sentinelWorkspaceName'))]"
      }
    }
  ]
}

PowerShell部署命令示例

将本地工作簿JSON数据(即原文档中的templateData)作为参数传入,执行部署:

New-AzResourceGroupDeployment -ResourceGroupName "your-resource-group-name" `
  -TemplateFile ".\sentinel-workbook-template.json" `
  -workbookName "My-Custom-Sentinel-Workbook" `
  -workbookDisplayName "Custom Sentinel Threat Monitor" `
  -sentinelWorkspaceName "your-sentinel-workspace-name" `
  -location "eastus" `
  -workbookSerializedData (Get-Content ".\your-workbook-template-data.json" -Raw)

验证部署结果

部署完成后,登录Azure门户进入目标Microsoft Sentinel实例,在工作簿菜单下即可看到部署的工作簿。

内容的提问来源于stack exchange,提问作者Jason Smyth

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 11:50:11