如何通过ARM模板(PowerShell执行)将工作簿部署至Microsoft Sentinel工作簿库?
将工作簿通过ARM模板部署到Microsoft Sentinel工作簿库的解决方案
要把工作簿部署到Microsoft Sentinel工作簿库而非Azure Monitor库,核心是修改ARM模板中的galleries配置和工作簿关联范围,具体操作如下:
关键ARM模板修改点
调整
galleries字段配置
替换原模板中galleries数组内的参数,将工作簿归类到Sentinel专属库:"galleries": [ { "name": "Sentinel", "category": "Workbooks", "resourceType": "Microsoft.SecurityInsights/workspaces", "galleryType": "shared" } ]绑定Sentinel工作区
在工作簿的properties中添加scope字段,指向目标Sentinel工作区的资源ID,确保工作簿与指定Sentinel实例关联:"scope": "[resourceId('Microsoft.SecurityInsights/workspaces', parameters('sentinelWorkspaceName'))]"匹配地理位置
确保工作簿的location参数与Sentinel工作区的地理位置完全一致,避免部署时出现区域不匹配错误。
完整ARM模板示例片段
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "workbookName": { "type": "string", "defaultValue": "Sentinel-Workbook-Demo" }, "workbookDisplayName": { "type": "string", "defaultValue": "Sentinel Threat Analytics Workbook" }, "sentinelWorkspaceName": { "type": "string" }, "location": { "type": "string" }, "workbookSerializedData": { "type": "string" } }, "resources": [ { "type": "Microsoft.Insights/workbooks", "apiVersion": "2021-08-01", "name": "[parameters('workbookName')]", "location": "[parameters('location')]", "kind": "shared", "properties": { "displayName": "[parameters('workbookDisplayName')]", "serializedData": "[parameters('workbookSerializedData')]", "version": "1.0", "galleries": [ { "name": "Sentinel", "category": "Workbooks", "resourceType": "Microsoft.SecurityInsights/workspaces", "galleryType": "shared" } ], "scope": "[resourceId('Microsoft.SecurityInsights/workspaces', parameters('sentinelWorkspaceName'))]" } } ] }
PowerShell部署命令示例
将本地工作簿JSON数据(即原文档中的templateData)作为参数传入,执行部署:
New-AzResourceGroupDeployment -ResourceGroupName "your-resource-group-name" ` -TemplateFile ".\sentinel-workbook-template.json" ` -workbookName "My-Custom-Sentinel-Workbook" ` -workbookDisplayName "Custom Sentinel Threat Monitor" ` -sentinelWorkspaceName "your-sentinel-workspace-name" ` -location "eastus" ` -workbookSerializedData (Get-Content ".\your-workbook-template-data.json" -Raw)
验证部署结果
部署完成后,登录Azure门户进入目标Microsoft Sentinel实例,在工作簿菜单下即可看到部署的工作簿。
内容的提问来源于stack exchange,提问作者Jason Smyth
相关产品推荐
相关产品推荐

