You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否通过PowerShell或API操作管理Azure Sentinel Watchlists

结论:操作完全可行

你可以和使用Az.SecurityInsights管理Sentinel规则一样,通过PowerShell对Azure Sentinel Watchlists执行全生命周期管理,完全支持你提到的「配置存储在VCS+脚本同步到远端」的使用需求。

核心实现说明

  • 依赖模块就是你已经在使用的Az.SecurityInsights,要求模块版本≥3.0.0,旧版本未集成Watchlist相关操作cmdlet,提前更新即可使用
  • 内置的Watchlist专属操作命令如下:
    • 查询现有Watchlist配置:Get-AzSecurityInsightsWatchlist
    • 创建全新Watchlist:New-AzSecurityInsightsWatchlist
    • 修改已存在的Watchlist配置或条目:Update-AzSecurityInsightsWatchlist
    • 删除指定Watchlist:Remove-AzSecurityInsightsWatchlist

VCS同步流程说明

你可以将Watchlist的元数据(别名、展示名、主键、描述等)存储为JSON文件,条目内容存储为CSV文件,全部提交到Git等版本控制系统中做版本管控。需要同步时运行PowerShell脚本读取本地配置文件,调用上述cmdlet即可直接将最新配置推送到Azure Sentinel环境,整个流程可以和你现有Sentinel规则的同步逻辑完全对齐。

极简同步示例参考:

# 登录Azure环境
Connect-AzAccount
# 配置Sentinel工作区参数
$rgName = "目标资源组名称"
$workspaceName = "Sentinel对应Log Analytics工作区名称"
# 读取本地VCS中存储的配置
$watchlistMeta = Get-Content "./sentinel-watchlists/allow-ip.json" | ConvertFrom-Json
$watchlistEntries = Import-Csv "./sentinel-watchlists/allow-ip-items.csv"
# 推送配置到远端
New-AzSecurityInsightsWatchlist -ResourceGroupName $rgName -WorkspaceName $workspaceName `
-WatchlistId $watchlistMeta.Id -DisplayName $watchlistMeta.DisplayName `
-PrimaryKey $watchlistMeta.PrimaryKey -Items $watchlistEntries

内容的提问来源于stack exchange,提问作者moutonjr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.07 09:06:04