使用CLI添加Microsoft Defender IP抑制规则时遇NotFound错误求助
解决Azure CLI添加Defender IP抑制规则时的NotFound错误
问题背景
已成功通过以下命令创建Microsoft Defender警报抑制规则:
az security alerts-suppression-rule update --rule-name TestRule --alert-type "SQL.DB_GeoAnomaly" --reason "Other" --state "Enabled" --subscription "xxxxxxx"
但执行以下命令为规则添加IP地址抑制范围时,持续触发NotFound错误:
az security alerts-suppression-rule upsert_scope --field "entities.ip.address" --contains-substring "xxx.x.x.xxx" --rule-name TestRule
目前公开资料中缺少针对IP地址的配置示例,微软官方文档仅提供了进程命令行字段的配置示例:
az security alerts-suppression-rule upsert_scope --field "entities.process.commandline" --contains-substring "example" --rule-name RuleName
排查与解决方案
1. 补充订阅参数
执行upsert_scope命令时必须指定与创建规则时一致的--subscription参数,否则CLI可能在错误的订阅中查找规则,导致NotFound:
az security alerts-suppression-rule upsert_scope --field "entities.ip.address" --contains-substring "xxx.x.x.xxx" --rule-name TestRule --subscription "xxxxxxx"
2. 验证字段路径正确性
不同类型的警报对应实体字段路径可能不同,以SQL.DB_GeoAnomaly警报为例,需确认其IP字段的正确路径:
- 登录Azure门户,找到同类型的历史警报,查看详情中的实体数据,确认IP对应的属性名
- 使用
az security alert show --alert-id <警报ID> --subscription "xxxxxxx"命令获取警报的JSON结构,检索IP相关字段的完整路径
3. 确认规则存在性
先通过以下命令验证目标规则是否存在于指定订阅中:
az security alerts-suppression-rule list --subscription "xxxxxxx"
若规则未列出,需重新创建规则后再执行upsert_scope操作。
4. 直接在创建规则时指定IP范围
可跳过后续的upsert_scope步骤,在创建规则时直接配置IP抑制范围:
az security alerts-suppression-rule create --rule-name TestRule --alert-type "SQL.DB_GeoAnomaly" --reason "Other" --state "Enabled" --subscription "xxxxxxx" --scope field="entities.ip.address" contains-substring="xxx.x.x.xxx"
内容的提问来源于stack exchange,提问作者Mumfi
相关产品推荐
相关产品推荐

