You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Logic App的KQL查询JSON结果转为可读格式用于Sentinel注释 enrichment

解决Microsoft Sentinel Logic App中KQL查询结果转可读HTML注释的方案

问题场景

已搭建用于Microsoft Sentinel enrichment与自动化的Logic App,针对「陌生登录」等身份类事件实现自动化。当前Logic App运行正常,其中通过「Run query and list results」操作执行以下KQL查询:

SigninLogs
| where UserPrincipalName == "<the upn variable>" // Replace with the specific user's UPN
| where UserAgent == "<the user-agent variable>" // Replace with the specific User-Agent string you're interested in
| where TimeGenerated between(ago(31d)..ago(1d)) // Filters to records from the last 30 days, excluding today
| summarize Count = count() by UserAgent, UserPrincipalName, AppDisplayName
| where Count > 0
| order by Count desc // Optional: Orders the results by count in descending order
| project Count, AppDisplayName, UserAgent, UserPrincipalName

查询返回JSON格式结果,但直接作为Sentinel事件注释可读性极差。该查询按事件中的User-Agent筛选指定用户过去30天(排除当日)的登录事件,按维度汇总计数,结果行数动态(0-4行)。此前尝试用数组变量转换未成功,现需可行的HTML转换方案。

实现步骤

  • 初始化HTML模板变量
    在Logic App中添加「Initialize variable」操作,变量类型选「String」,命名为HTMLTableOutput,初始值设为:

    <table border="1" cellpadding="4" cellspacing="0">
      <tr>
        <th>登录次数</th>
        <th>应用名称</th>
        <th>User-Agent</th>
        <th>用户UPN</th>
      </tr>
    
  • 遍历查询结果生成表格行
    添加「For each」循环,选择「Run query and list results」返回的value数组作为循环输入。在循环内部添加「Append to string variable」操作,将每一行结果转为HTML行:

    <tr>
        <td>@{items('For_each')?['Count']}</td>
        <td>@{items('For_each')?['AppDisplayName']}</td>
        <td>@{items('For_each')?['UserAgent']}</td>
        <td>@{items('For_each')?['UserPrincipalName']}</td>
      </tr>
    
  • 闭合HTML表格
    循环结束后,添加「Append to string variable」操作,给HTMLTableOutput追加表格闭合标签:

    </table>
    
  • 处理空结果场景
    添加「Condition」操作,判断「Run query and list results」返回的value数组长度是否为0。若为空,将HTMLTableOutput替换为:<p>过去30天内无匹配该User-Agent的登录记录</p>

  • 添加到事件注释
    在「Add comment to incident」操作中,直接引用HTMLTableOutput变量作为注释内容即可。

内容的提问来源于stack exchange,提问作者D3F3ND3R

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 09:43:29