You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Sentinel定时告警创建EntityMapping对象?PowerShell 5.1适配问题

PowerShell 5.1创建带EntityMapping的Sentinel定时告警规则报错问题

我尝试在Runbook中通过PowerShell命令创建带有EntityMapping参数的Sentinel定时告警规则。在PowerShell 5.1版本中,将嵌套JSON转换为哈希表并作为EntityMapping参数传入时出现报错,但PowerShell 7.1版本使用ConvertFrom-Json -AsHashTable可正常运行。

5.1版本代码

$json =  '[\n  {\n    \"EntityType\": \"IP\",\n    \"FieldMapping\": [\n      {\n        \"ColumnName\": \"FileHashCustomEntity\",\n        \"Identifier\": \"Address\"\n      }\n    ]\n  }\n]'


function Convert-PSCToHashTable
{
  param(
    $InputObject, 
    [int]$Depth = 5
  )

  if($Depth -gt 0){
    if($InputObject -is [System.Collections.IList]){
      return @($InputObject |ForEach-Object {Convert-PSCToHashTable $_ -Depth ($Depth - 1)})
    }

    if($InputObject.psobject.BaseObject -is [System.Management.Automation.PSCustomObject]){
      $ht = @{}
      foreach($prop in $InputObject.psobject.Properties){
        $ht[$prop.Name] = Convert-PSCToHashTable $prop.Value -Depth ($Depth - 1)
      }
      return $ht
    }
  }

  return $InputObject
}
$object = ConvertFrom-Json $json
$hashtable = Convert-PSCToHashTable $object
echo $hashtable
New-AzSentinelAlertRule   -ResourceGroupName $ResourceGroupName -WorkspaceName $WorkspaceName  -QueryFrequency 1:00:00   -QueryPeriod 1:00:00 -DisplayName \"TesS-2\"   -Kind Scheduled   -Query \"SecurityAlert | where TimeGenerated == '99'\"   -Severity Low    -TriggerOperator GreaterThan -TriggerThreshold 10 -EntityMapping $hashtable

报错信息

Name                           Value                                                                                    
----                           -----                                                                                    
FieldMapping                   {Identifier, ColumnName}                                                                  
EntityType                     IP                                                                                       


[BadRequest] : Invalid data model. [: Invalid length of '0' for 'FieldMappings'. 'FieldMappings' length should be between '1' and '3']
System.Management.Automation.ParameterBindingException: Parameter set cannot be resolved using the specified named parameters.

7.1版本可行代码

$entities = $json | ConvertFrom-Json -AsHashTable
 
New-AzSentinelAlertRule   -ResourceGroupName \"myResourceGroupName\" -WorkspaceName \"myWorkspaceName\"  -QueryFrequency 1:00:00   -QueryPeriod 1:00:00 -DisplayName \"TesS-2\"   -Kind Scheduled   -Query \"SecurityAlert | where TimeGenerated == '99'\"   -Severity Low    -TriggerOperator GreaterThan -TriggerThreshold 10 -EntityMapping $entities

问题原因与修复方案

原因

PowerShell 5.1自带的ConvertFrom-Json仅返回PSCustomObject,自定义的Convert-PSCToHashTable函数在处理FieldMapping这类嵌套数组时,未正确保留数组结构,导致FieldMapping被解析为单个哈希表而非数组,不符合New-AzSentinelAlertRule对EntityMapping参数的格式要求(需要数组类型的FieldMappings)。

修复后的转换函数

修改Convert-PSCToHashTable函数,确保处理数组类型时明确返回哈希表数组:

function Convert-PSCToHashTable
{
  param(
    $InputObject, 
    [int]$Depth = 5
  )

  if ($Depth -le 0) {
    return $InputObject
  }

  # 处理数组/列表类型,保留数组结构
  if ($InputObject -is [System.Collections.IList]) {
    $resultArray = @()
    foreach ($item in $InputObject) {
      $resultArray += Convert-PSCToHashTable $item -Depth ($Depth - 1)
    }
    return $resultArray
  }

  # 处理PSCustomObject转换为哈希表
  if ($InputObject -is [System.Management.Automation.PSCustomObject]) {
    $hashTable = @{}
    foreach ($prop in $InputObject.psobject.Properties) {
      $hashTable[$prop.Name] = Convert-PSCToHashTable $prop.Value -Depth ($Depth - 1)
    }
    return $hashTable
  }

  return $InputObject
}

替换原函数后,重新执行5.1版本代码即可正常创建告警规则。

内容的提问来源于stack exchange,提问作者dev333

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 03:45:53