You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Sentinel分析规则问题:24小时无结果(Cisco防火墙事件关联)

Azure Sentinel分析规则Inner Join时间范围问题排查与解决

我在Azure Sentinel中配置了针对Cisco Firepower防火墙事件的分析规则,通过Inner Join将CommonSecurityLog中的源IP与ThreatIntelligenceIndicator表的恶意IP比对,识别允许的外部恶意IP访问内部私有IP的行为。规则查询语句如下:

CommonSecurityLog
| join kind=inner ThreatIntelligenceIndicator on $left.SourceIP == $right.NetworkIP
| where SourceIP == NetworkIP
| where DeviceVendor == 'Cisco' and DeviceProduct == 'Firepower'
| where DeviceAction == 'Allow'
| where ipv4_is_private(SourceIP) == false
| where ipv4_is_private(DestinationIP) == true
| project TimeGenerated, DeviceAction, SourceIP, DestinationIP, DestinationPort

遇到的问题:设置24小时时间范围(10月15日当天)运行查询无结果,但设置7天时间范围时能返回包含过去24小时内的事件;单独查询CommonSecurityLog(注释Join语句)能正常显示24小时内的事件,判断问题出在Inner Join环节。


问题根源

Inner Join要求关联的两张表在当前查询的时间范围内都存在匹配记录。你的场景中:

  • 24小时时间范围下,ThreatIntelligenceIndicator表中可能没有对应匹配的恶意IP记录(比如情报是7天内生成的,24小时时间范围被过滤;或者情报已过期被系统移除)
  • 7天时间范围包含了情报的生成/有效周期,因此能匹配到24小时内的防火墙事件

优化后的查询语句

// 先过滤防火墙事件,减少Join数据量
CommonSecurityLog
| where DeviceVendor == 'Cisco' and DeviceProduct == 'Firepower'
| where DeviceAction == 'Allow'
| where ipv4_is_private(SourceIP) == false
| where ipv4_is_private(DestinationIP) == true
// 关联威胁情报表,指定情报的时间范围(覆盖恶意IP的有效周期)
| join kind=inner hint.strategy=broadcast (
    ThreatIntelligenceIndicator
    | where TimeGenerated >= ago(7d)  // 保留过去7天的情报,可根据实际情报更新周期调整
    | where isnotempty(NetworkIP)
) on SourceIP == NetworkIP
| project 
    TimeGenerated, 
    DeviceAction, 
    SourceIP, 
    DestinationIP, 
    DestinationPort,
    ThreatType,  // 新增情报字段辅助分析恶意类型
    Confidence   // 新增情报置信度字段

关键修改说明

  1. 前置过滤日志:先对CommonSecurityLog做条件过滤,减少参与Join的数据量,大幅提升查询性能
  2. 指定情报时间范围:给ThreatIntelligenceIndicator单独设置时间范围(比如过去7天),确保24小时内的防火墙事件能匹配到历史有效情报
  3. 使用Broadcast策略:ThreatIntelligenceIndicator通常数据量远小于日志表,hint.strategy=broadcast能优化Join执行效率
  4. 移除重复条件:where SourceIP == NetworkIP是冗余条件,Join已建立关联,无需重复判断

排查验证步骤

  1. 检查24小时内是否有匹配的情报:
ThreatIntelligenceIndicator
| where TimeGenerated >= ago(24h)
| where NetworkIP in (dynamic(["你观察到的恶意源IP"]))
  1. 检查情报的过期时间:
ThreatIntelligenceIndicator
| where NetworkIP == "目标IP"
| project NetworkIP, ExpirationDateTime, TimeGenerated

如果ExpirationDateTime早于当前时间,说明情报已过期,无法参与匹配。

内容的提问来源于stack exchange,提问作者Miguel Cuba

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 08:40:21