如何为Sentinel定时告警创建EntityMapping对象?PowerShell 5.1适配问题
PowerShell 5.1创建带EntityMapping的Sentinel定时告警规则报错问题
我尝试在Runbook中通过PowerShell命令创建带有EntityMapping参数的Sentinel定时告警规则。在PowerShell 5.1版本中,将嵌套JSON转换为哈希表并作为EntityMapping参数传入时出现报错,但PowerShell 7.1版本使用ConvertFrom-Json -AsHashTable可正常运行。
5.1版本代码
$json = '[\n {\n \"EntityType\": \"IP\",\n \"FieldMapping\": [\n {\n \"ColumnName\": \"FileHashCustomEntity\",\n \"Identifier\": \"Address\"\n }\n ]\n }\n]' function Convert-PSCToHashTable { param( $InputObject, [int]$Depth = 5 ) if($Depth -gt 0){ if($InputObject -is [System.Collections.IList]){ return @($InputObject |ForEach-Object {Convert-PSCToHashTable $_ -Depth ($Depth - 1)}) } if($InputObject.psobject.BaseObject -is [System.Management.Automation.PSCustomObject]){ $ht = @{} foreach($prop in $InputObject.psobject.Properties){ $ht[$prop.Name] = Convert-PSCToHashTable $prop.Value -Depth ($Depth - 1) } return $ht } } return $InputObject } $object = ConvertFrom-Json $json $hashtable = Convert-PSCToHashTable $object echo $hashtable New-AzSentinelAlertRule -ResourceGroupName $ResourceGroupName -WorkspaceName $WorkspaceName -QueryFrequency 1:00:00 -QueryPeriod 1:00:00 -DisplayName \"TesS-2\" -Kind Scheduled -Query \"SecurityAlert | where TimeGenerated == '99'\" -Severity Low -TriggerOperator GreaterThan -TriggerThreshold 10 -EntityMapping $hashtable
报错信息
Name Value ---- ----- FieldMapping {Identifier, ColumnName} EntityType IP [BadRequest] : Invalid data model. [: Invalid length of '0' for 'FieldMappings'. 'FieldMappings' length should be between '1' and '3'] System.Management.Automation.ParameterBindingException: Parameter set cannot be resolved using the specified named parameters.
7.1版本可行代码
$entities = $json | ConvertFrom-Json -AsHashTable New-AzSentinelAlertRule -ResourceGroupName \"myResourceGroupName\" -WorkspaceName \"myWorkspaceName\" -QueryFrequency 1:00:00 -QueryPeriod 1:00:00 -DisplayName \"TesS-2\" -Kind Scheduled -Query \"SecurityAlert | where TimeGenerated == '99'\" -Severity Low -TriggerOperator GreaterThan -TriggerThreshold 10 -EntityMapping $entities
问题原因与修复方案
原因
PowerShell 5.1自带的ConvertFrom-Json仅返回PSCustomObject,自定义的Convert-PSCToHashTable函数在处理FieldMapping这类嵌套数组时,未正确保留数组结构,导致FieldMapping被解析为单个哈希表而非数组,不符合New-AzSentinelAlertRule对EntityMapping参数的格式要求(需要数组类型的FieldMappings)。
修复后的转换函数
修改Convert-PSCToHashTable函数,确保处理数组类型时明确返回哈希表数组:
function Convert-PSCToHashTable { param( $InputObject, [int]$Depth = 5 ) if ($Depth -le 0) { return $InputObject } # 处理数组/列表类型,保留数组结构 if ($InputObject -is [System.Collections.IList]) { $resultArray = @() foreach ($item in $InputObject) { $resultArray += Convert-PSCToHashTable $item -Depth ($Depth - 1) } return $resultArray } # 处理PSCustomObject转换为哈希表 if ($InputObject -is [System.Management.Automation.PSCustomObject]) { $hashTable = @{} foreach ($prop in $InputObject.psobject.Properties) { $hashTable[$prop.Name] = Convert-PSCToHashTable $prop.Value -Depth ($Depth - 1) } return $hashTable } return $InputObject }
替换原函数后,重新执行5.1版本代码即可正常创建告警规则。
内容的提问来源于stack exchange,提问作者dev333
相关产品推荐
相关产品推荐

