You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过API为Azure Sentinel事件添加alertProductNames

解决Azure Sentinel Incident API中alertProductNames字段无法填充的问题

问题原因

alertProductNames是只读派生字段,它的值是从与Incident关联的Alert的productName字段自动聚合而来的,无法通过直接在Incident的PUT/POST请求体中写入该字段来填充。

解决方案

要让alertProductNames显示对应的值,你需要在Incident的请求体中关联已存在的Alert资源,系统会自动将这些Alert的productName聚合到Incident的alertProductNames字段中。

具体步骤

  1. 获取或创建目标Alert:确保你有要关联的Alert的完整资源ID(格式为/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/alerts/{alertId})。
  2. 在Incident请求体中添加关联Alerts:在请求体的properties下加入relatedAlerts数组,填入Alert的资源ID。

示例请求体(PUT更新Incident)

{
  "properties": {
    "title": "Updated Incident with Linked Alerts",
    "description": "Incident linked to alerts from specific security products",
    "severity": "High",
    "status": "Active",
    "relatedAlerts": [
      "/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/alerts/{alertId1}",
      "/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/alerts/{alertId2}"
    ]
  }
}

验证结果

发送请求后,返回的Incident对象中alertProductNames字段会自动填充为关联Alert的productName值的集合,无需手动设置。

注意:如果是创建新Incident,推荐使用POST请求到Incidents集合端点,而非PUT(PUT通常用于更新已有资源):
POST https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/incidents?api-version=2022-12-01-preview

内容的提问来源于stack exchange,提问作者hamzahjazi98

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 21:39:36