You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用msticpy更新Azure Sentinel事件标签遇400错误,求技术支援

解决Azure Sentinel事件标签更新失败的问题

问题描述

使用msticpy更新Azure Sentinel事件标签时API返回400错误,但修改事件其他属性正常。环境信息:

  • Python 3.10
  • Azure Machine Learning Studio notebook
  • msticpy 2.11

使用代码:

from msticpy.data.azure import AzureData, MicrosoftSentinel
azs = MicrosoftSentinel()
azs.connect()
azs.update_incident(incident_id = "INCIDENTID8", update_items = {'labels': 
[{'labelName': 'test', 'labelType': 'User'}]})

报错信息:

HTTPStatusError: 客户端错误“400 Bad Request”,请求地址:https://management.azure.com/subscriptions/SUBSCRIPTIONID/resourceGroups/RESOURCEGROUP/providers/Microsoft.OperationalInsights/workspaces/WORKSPACE/providers/Microsoft.SecurityInsights/incidents/INCIDENTID?api-version=2020-01-01

解决方法

问题出在标签参数的键名错误。当前使用的labelName和labelType不符合目标API版本(2020-01-01)的字段要求,正确的键名应为name和type。修改代码如下:

from msticpy.data.azure import AzureData, MicrosoftSentinel
azs = MicrosoftSentinel()
azs.connect()
azs.update_incident(incident_id = "INCIDENTID8", update_items = {'labels': 
[{'name': 'test', 'type': 'User'}]})

另外,若需要更完善的标签支持,可以在初始化MicrosoftSentinel时指定更高版本的API,比如2023-02-01:

azs = MicrosoftSentinel(api_version="2023-02-01")

内容的提问来源于stack exchange,提问作者glwallum

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 18:43:13