Sentinel分析规则问题:24小时无结果(Cisco防火墙事件关联)
Azure Sentinel分析规则Inner Join时间范围问题排查与解决
我在Azure Sentinel中配置了针对Cisco Firepower防火墙事件的分析规则,通过Inner Join将CommonSecurityLog中的源IP与ThreatIntelligenceIndicator表的恶意IP比对,识别允许的外部恶意IP访问内部私有IP的行为。规则查询语句如下:
CommonSecurityLog | join kind=inner ThreatIntelligenceIndicator on $left.SourceIP == $right.NetworkIP | where SourceIP == NetworkIP | where DeviceVendor == 'Cisco' and DeviceProduct == 'Firepower' | where DeviceAction == 'Allow' | where ipv4_is_private(SourceIP) == false | where ipv4_is_private(DestinationIP) == true | project TimeGenerated, DeviceAction, SourceIP, DestinationIP, DestinationPort
遇到的问题:设置24小时时间范围(10月15日当天)运行查询无结果,但设置7天时间范围时能返回包含过去24小时内的事件;单独查询CommonSecurityLog(注释Join语句)能正常显示24小时内的事件,判断问题出在Inner Join环节。
问题根源
Inner Join要求关联的两张表在当前查询的时间范围内都存在匹配记录。你的场景中:
- 24小时时间范围下,ThreatIntelligenceIndicator表中可能没有对应匹配的恶意IP记录(比如情报是7天内生成的,24小时时间范围被过滤;或者情报已过期被系统移除)
- 7天时间范围包含了情报的生成/有效周期,因此能匹配到24小时内的防火墙事件
优化后的查询语句
// 先过滤防火墙事件,减少Join数据量 CommonSecurityLog | where DeviceVendor == 'Cisco' and DeviceProduct == 'Firepower' | where DeviceAction == 'Allow' | where ipv4_is_private(SourceIP) == false | where ipv4_is_private(DestinationIP) == true // 关联威胁情报表,指定情报的时间范围(覆盖恶意IP的有效周期) | join kind=inner hint.strategy=broadcast ( ThreatIntelligenceIndicator | where TimeGenerated >= ago(7d) // 保留过去7天的情报,可根据实际情报更新周期调整 | where isnotempty(NetworkIP) ) on SourceIP == NetworkIP | project TimeGenerated, DeviceAction, SourceIP, DestinationIP, DestinationPort, ThreatType, // 新增情报字段辅助分析恶意类型 Confidence // 新增情报置信度字段
关键修改说明
- 前置过滤日志:先对CommonSecurityLog做条件过滤,减少参与Join的数据量,大幅提升查询性能
- 指定情报时间范围:给ThreatIntelligenceIndicator单独设置时间范围(比如过去7天),确保24小时内的防火墙事件能匹配到历史有效情报
- 使用Broadcast策略:ThreatIntelligenceIndicator通常数据量远小于日志表,
hint.strategy=broadcast能优化Join执行效率 - 移除重复条件:
where SourceIP == NetworkIP是冗余条件,Join已建立关联,无需重复判断
排查验证步骤
- 检查24小时内是否有匹配的情报:
ThreatIntelligenceIndicator | where TimeGenerated >= ago(24h) | where NetworkIP in (dynamic(["你观察到的恶意源IP"]))
- 检查情报的过期时间:
ThreatIntelligenceIndicator | where NetworkIP == "目标IP" | project NetworkIP, ExpirationDateTime, TimeGenerated
如果ExpirationDateTime早于当前时间,说明情报已过期,无法参与匹配。
内容的提问来源于stack exchange,提问作者Miguel Cuba
相关产品推荐
相关产品推荐

