You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用CLI添加Microsoft Defender IP抑制规则时遇NotFound错误求助

解决Azure CLI添加Defender IP抑制规则时的NotFound错误

问题背景

已成功通过以下命令创建Microsoft Defender警报抑制规则:

az security alerts-suppression-rule update --rule-name TestRule --alert-type "SQL.DB_GeoAnomaly" --reason "Other" --state "Enabled" --subscription "xxxxxxx"

但执行以下命令为规则添加IP地址抑制范围时,持续触发NotFound错误:

az security alerts-suppression-rule upsert_scope --field "entities.ip.address" --contains-substring "xxx.x.x.xxx" --rule-name TestRule

目前公开资料中缺少针对IP地址的配置示例,微软官方文档仅提供了进程命令行字段的配置示例:

az security alerts-suppression-rule upsert_scope --field "entities.process.commandline" --contains-substring "example" --rule-name RuleName

排查与解决方案

1. 补充订阅参数

执行upsert_scope命令时必须指定与创建规则时一致的--subscription参数,否则CLI可能在错误的订阅中查找规则,导致NotFound:

az security alerts-suppression-rule upsert_scope --field "entities.ip.address" --contains-substring "xxx.x.x.xxx" --rule-name TestRule --subscription "xxxxxxx"

2. 验证字段路径正确性

不同类型的警报对应实体字段路径可能不同,以SQL.DB_GeoAnomaly警报为例,需确认其IP字段的正确路径:

  • 登录Azure门户,找到同类型的历史警报,查看详情中的实体数据,确认IP对应的属性名
  • 使用az security alert show --alert-id <警报ID> --subscription "xxxxxxx"命令获取警报的JSON结构,检索IP相关字段的完整路径

3. 确认规则存在性

先通过以下命令验证目标规则是否存在于指定订阅中:

az security alerts-suppression-rule list --subscription "xxxxxxx"

若规则未列出,需重新创建规则后再执行upsert_scope操作。

4. 直接在创建规则时指定IP范围

可跳过后续的upsert_scope步骤,在创建规则时直接配置IP抑制范围:

az security alerts-suppression-rule create --rule-name TestRule --alert-type "SQL.DB_GeoAnomaly" --reason "Other" --state "Enabled" --subscription "xxxxxxx" --scope field="entities.ip.address" contains-substring="xxx.x.x.xxx"

内容的提问来源于stack exchange,提问作者Mumfi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 14:32:30