如何将Logic App的KQL查询JSON结果转为可读格式用于Sentinel注释 enrichment
问题场景
已搭建用于Microsoft Sentinel enrichment与自动化的Logic App,针对「陌生登录」等身份类事件实现自动化。当前Logic App运行正常,其中通过「Run query and list results」操作执行以下KQL查询:
SigninLogs | where UserPrincipalName == "<the upn variable>" // Replace with the specific user's UPN | where UserAgent == "<the user-agent variable>" // Replace with the specific User-Agent string you're interested in | where TimeGenerated between(ago(31d)..ago(1d)) // Filters to records from the last 30 days, excluding today | summarize Count = count() by UserAgent, UserPrincipalName, AppDisplayName | where Count > 0 | order by Count desc // Optional: Orders the results by count in descending order | project Count, AppDisplayName, UserAgent, UserPrincipalName
查询返回JSON格式结果,但直接作为Sentinel事件注释可读性极差。该查询按事件中的User-Agent筛选指定用户过去30天(排除当日)的登录事件,按维度汇总计数,结果行数动态(0-4行)。此前尝试用数组变量转换未成功,现需可行的HTML转换方案。
实现步骤
初始化HTML模板变量
在Logic App中添加「Initialize variable」操作,变量类型选「String」,命名为HTMLTableOutput,初始值设为:<table border="1" cellpadding="4" cellspacing="0"> <tr> <th>登录次数</th> <th>应用名称</th> <th>User-Agent</th> <th>用户UPN</th> </tr>遍历查询结果生成表格行
添加「For each」循环,选择「Run query and list results」返回的value数组作为循环输入。在循环内部添加「Append to string variable」操作,将每一行结果转为HTML行:<tr> <td>@{items('For_each')?['Count']}</td> <td>@{items('For_each')?['AppDisplayName']}</td> <td>@{items('For_each')?['UserAgent']}</td> <td>@{items('For_each')?['UserPrincipalName']}</td> </tr>闭合HTML表格
循环结束后,添加「Append to string variable」操作,给HTMLTableOutput追加表格闭合标签:</table>处理空结果场景
添加「Condition」操作,判断「Run query and list results」返回的value数组长度是否为0。若为空,将HTMLTableOutput替换为:<p>过去30天内无匹配该User-Agent的登录记录</p>添加到事件注释
在「Add comment to incident」操作中,直接引用HTMLTableOutput变量作为注释内容即可。
内容的提问来源于stack exchange,提问作者D3F3ND3R

