如何通过az-cli创建Sentinel告警?遇‘kind字段不存在’错误求助
解决Azure CLI创建Sentinel告警规则时的"Model 'AAZObjectType' has no field named 'kind'"错误
问题根源
这个错误的核心原因是创建Sentinel告警规则时缺少规则类型(kind参数),同时可能存在Azure CLI或Sentinel扩展版本兼容性问题。不同类型的告警规则(如Scheduled、Fusion、MLBehaviorAnalytics)对应不同的配置模型,缺失kind会导致CLI无法正确识别要生成的规则结构。另外,原命令中的中文破折号(—-)也可能引发参数解析异常。
解决步骤
1. 修正命令参数格式
先将命令中的中文破折号替换为英文半角破折号(--),确保参数解析正常:
az sentinel alert-rule create --name "test" --resource-group example-resources --workspace-name example-workspace
2. 升级Azure CLI及Sentinel扩展
旧版本的CLI或Sentinel扩展可能存在模型定义缺陷,执行以下命令升级到最新版本:
# 升级Azure CLI主程序 az upgrade # 更新Sentinel扩展 az extension update --name sentinel
3. 指定告警规则类型并补充必填参数
根据需求选择规则类型,添加--kind参数及对应类型的必填配置:
示例:创建定时查询规则(Scheduled)
这是最常用的自定义规则类型,需指定查询语句、执行频率、严重性等参数:
az sentinel alert-rule create \ --name "test-failed-login-alert" \ --resource-group example-resources \ --workspace-name example-workspace \ --kind Scheduled \ --query "SecurityEvent | where EventID == '4625'" \ --frequency 5 \ --severity Medium \ --trigger-threshold 1 \ --description "Alert on failed Windows login attempts"
查看其他规则类型的参数要求
如果需要创建Fusion或其他类型的规则,可通过以下命令查看对应类型的必填参数:
az sentinel alert-rule create --help
在帮助信息中定位目标kind类型的参数说明,补充完整后再执行创建命令。
4. 验证规则创建结果
命令执行成功后,可通过以下命令确认规则已生成:
az sentinel alert-rule list --resource-group example-resources --workspace-name example-workspace --query "[?name=='test-failed-login-alert']"
内容的提问来源于stack exchange,提问作者dev333
相关产品推荐
相关产品推荐

