如何使用PowerShell或Azure CLI克隆Microsoft Sentinel分析规则
克隆Microsoft Sentinel分析规则(PowerShell & Azure CLI)
PowerShell 实现方案
前置准备
确保已安装并导入Az.Sentinel模块:
Install-Module -Name Az.Sentinel -Force -AllowClobber Import-Module Az.Sentinel
修正后的克隆脚本
$resourceGroupName = "XYZ" $workspaceName = "abc" # 获取目标工作区下所有分析规则 $analyticRules = Get-AzSentinelAlertRule -ResourceGroupName $resourceGroupName -WorkspaceName $workspaceName foreach ($rule in $analyticRules) { # 创建规则副本(避免直接引用原对象导致修改原规则) $newRule = $rule.PSObject.Copy() # 修改显示名称,添加前缀区分克隆规则 $newRule.DisplayName = "副本_" + $rule.DisplayName # 清空原有ID和资源名称,让系统自动生成新的ruleId $newRule.Id = $null $newRule.Name = $null # 创建克隆规则,根据规则类型补充对应参数 New-AzSentinelAlertRule -ResourceGroupName $resourceGroupName ` -WorkspaceName $workspaceName ` -DisplayName $newRule.DisplayName ` -Description $newRule.Description ` -Severity $newRule.Severity ` -Enabled $newRule.Enabled ` -Query $newRule.Query ` -QueryFrequency $newRule.QueryFrequency ` -QueryPeriod $newRule.QueryPeriod ` -TriggerOperator $newRule.TriggerOperator ` -TriggerThreshold $newRule.TriggerThreshold ` -SuppressionDuration $newRule.SuppressionDuration ` -SuppressionEnabled $newRule.SuppressionEnabled ` -Tactics $newRule.Tactics ` -Techniques $newRule.Techniques ` -IncidentConfiguration $newRule.IncidentConfiguration }
- 若规则包含
EntityMappings等其他自定义属性,需在New-AzSentinelAlertRule命令中添加对应参数传递。
Azure CLI 实现方案
前置准备
- 登录Azure并切换到目标订阅:
az login az account set --subscription <你的订阅ID>
- 安装
jq工具(用于JSON内容修改)。
克隆脚本
RESOURCE_GROUP="XYZ" WORKSPACE_NAME="abc" # 获取所有分析规则的ID列表 RULE_IDS=$(az sentinel alert-rule list --resource-group $RESOURCE_GROUP --workspace-name $WORKSPACE_NAME --query "[].name" -o tsv) for RULE_ID in $RULE_IDS; do # 导出原规则的JSON配置 az sentinel alert-rule show --resource-group $RESOURCE_GROUP --workspace-name $WORKSPACE_NAME --name $RULE_ID -o json > rule_config.json # 修改显示名称并清空原有ID字段 jq '.displayName = "副本_" + .displayName | .id = null' rule_config.json > new_rule_config.json # 生成唯一规则名称(对应ruleId)并创建克隆规则 az sentinel alert-rule create --resource-group $RESOURCE_GROUP --workspace-name $WORKSPACE_NAME --name $(uuidgen) --properties @new_rule_config.json # 清理临时文件 rm rule_config.json new_rule_config.json done
内容的提问来源于stack exchange,提问作者Jason Smyth
相关产品推荐
相关产品推荐

