使用msticpy更新Azure Sentinel事件标签遇400错误,求技术支援
解决Azure Sentinel事件标签更新失败的问题
问题描述
使用msticpy更新Azure Sentinel事件标签时API返回400错误,但修改事件其他属性正常。环境信息:
- Python 3.10
- Azure Machine Learning Studio notebook
- msticpy 2.11
使用代码:
from msticpy.data.azure import AzureData, MicrosoftSentinel azs = MicrosoftSentinel() azs.connect() azs.update_incident(incident_id = "INCIDENTID8", update_items = {'labels': [{'labelName': 'test', 'labelType': 'User'}]})
报错信息:
HTTPStatusError: 客户端错误“400 Bad Request”,请求地址:https://management.azure.com/subscriptions/SUBSCRIPTIONID/resourceGroups/RESOURCEGROUP/providers/Microsoft.OperationalInsights/workspaces/WORKSPACE/providers/Microsoft.SecurityInsights/incidents/INCIDENTID?api-version=2020-01-01
解决方法
问题出在标签参数的键名错误。当前使用的labelName和labelType不符合目标API版本(2020-01-01)的字段要求,正确的键名应为name和type。修改代码如下:
from msticpy.data.azure import AzureData, MicrosoftSentinel azs = MicrosoftSentinel() azs.connect() azs.update_incident(incident_id = "INCIDENTID8", update_items = {'labels': [{'name': 'test', 'type': 'User'}]})
另外,若需要更完善的标签支持,可以在初始化MicrosoftSentinel时指定更高版本的API,比如2023-02-01:
azs = MicrosoftSentinel(api_version="2023-02-01")
内容的提问来源于stack exchange,提问作者glwallum
相关产品推荐
相关产品推荐

