You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用PowerShell或Azure CLI克隆Microsoft Sentinel分析规则

克隆Microsoft Sentinel分析规则(PowerShell & Azure CLI)

PowerShell 实现方案

前置准备

确保已安装并导入Az.Sentinel模块:

Install-Module -Name Az.Sentinel -Force -AllowClobber
Import-Module Az.Sentinel

修正后的克隆脚本

$resourceGroupName = "XYZ" 
$workspaceName = "abc"

# 获取目标工作区下所有分析规则
$analyticRules = Get-AzSentinelAlertRule -ResourceGroupName $resourceGroupName -WorkspaceName $workspaceName 

foreach ($rule in $analyticRules) {
    # 创建规则副本(避免直接引用原对象导致修改原规则)
    $newRule = $rule.PSObject.Copy()
    
    # 修改显示名称,添加前缀区分克隆规则
    $newRule.DisplayName = "副本_" + $rule.DisplayName
    
    # 清空原有ID和资源名称,让系统自动生成新的ruleId
    $newRule.Id = $null
    $newRule.Name = $null

    # 创建克隆规则,根据规则类型补充对应参数
    New-AzSentinelAlertRule -ResourceGroupName $resourceGroupName `
                            -WorkspaceName $workspaceName `
                            -DisplayName $newRule.DisplayName `
                            -Description $newRule.Description `
                            -Severity $newRule.Severity `
                            -Enabled $newRule.Enabled `
                            -Query $newRule.Query `
                            -QueryFrequency $newRule.QueryFrequency `
                            -QueryPeriod $newRule.QueryPeriod `
                            -TriggerOperator $newRule.TriggerOperator `
                            -TriggerThreshold $newRule.TriggerThreshold `
                            -SuppressionDuration $newRule.SuppressionDuration `
                            -SuppressionEnabled $newRule.SuppressionEnabled `
                            -Tactics $newRule.Tactics `
                            -Techniques $newRule.Techniques `
                            -IncidentConfiguration $newRule.IncidentConfiguration
}
  • 若规则包含EntityMappings等其他自定义属性,需在New-AzSentinelAlertRule命令中添加对应参数传递。

Azure CLI 实现方案

前置准备

  • 登录Azure并切换到目标订阅:
az login
az account set --subscription <你的订阅ID>
  • 安装jq工具(用于JSON内容修改)。

克隆脚本

RESOURCE_GROUP="XYZ"
WORKSPACE_NAME="abc"

# 获取所有分析规则的ID列表
RULE_IDS=$(az sentinel alert-rule list --resource-group $RESOURCE_GROUP --workspace-name $WORKSPACE_NAME --query "[].name" -o tsv)

for RULE_ID in $RULE_IDS; do
    # 导出原规则的JSON配置
    az sentinel alert-rule show --resource-group $RESOURCE_GROUP --workspace-name $WORKSPACE_NAME --name $RULE_ID -o json > rule_config.json
    
    # 修改显示名称并清空原有ID字段
    jq '.displayName = "副本_" + .displayName | .id = null' rule_config.json > new_rule_config.json
    
    # 生成唯一规则名称(对应ruleId)并创建克隆规则
    az sentinel alert-rule create --resource-group $RESOURCE_GROUP --workspace-name $WORKSPACE_NAME --name $(uuidgen) --properties @new_rule_config.json
    
    # 清理临时文件
    rm rule_config.json new_rule_config.json
done

内容的提问来源于stack exchange,提问作者Jason Smyth

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 16:46:19