如何将SecurityAlert表中的IP与AzureIPTable中的子网匹配校验
解决方案
要实现从SecurityAlert表中筛选出属于AzureIPTable表子网范围内的IP地址,你可以参考以下修正后的KQL语句:
// 提取SecurityAlert中去重的有效IPv4地址 let TargetIPs = SecurityAlert | mv-expand parse_json(Entities) | evaluate bag_unpack(Entities, columnsConflict='keep_source') | where isnotempty(Address) and ipv4_is_valid(Address) // 过滤空值和无效IP | distinct Address; // 筛选出属于AzureIPTable子网的IP TargetIPs | where exists ( AzureIPTable | where ipv4_is_in_range(TargetIPs.Address, addressPrefixes) )
原语句的问题说明
- 函数参数错误:
ipv4_is_in_range()的第一个参数需要是单个IP地址,而非整个IP集合,原语句直接传入IPs集合会导致逻辑错误。 - 关联逻辑缺失:原语句仅在
AzureIPTable中添加列,未建立IP与子网的匹配关联,无法筛选出符合条件的IP。
补充说明
如果需要同时返回对应的子网信息,可以改用join搭配ipv4_is_in_range的方式:
let TargetIPs = SecurityAlert | mv-expand parse_json(Entities) | evaluate bag_unpack(Entities, columnsConflict='keep_source') | where isnotempty(Address) and ipv4_is_valid(Address) | distinct Address; TargetIPs | join kind=inner (AzureIPTable) on $left.Address has_any $right.addressPrefixes | where ipv4_is_in_range(Address, addressPrefixes) | project Address, addressPrefixes
内容的提问来源于stack exchange,提问作者HarriS
相关产品推荐
相关产品推荐

