-
Notifications
You must be signed in to change notification settings - Fork 3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Analytic Rules with subtechniques fail to deploy #8960
Comments
Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal. |
Hi @ thanks for flagging this issue, we will soon get back to you on this. Thanks! |
Hello @Kaloszer, please can you install the |
@v-sudkharat No, analytic rules should be deployable using their arm templates, this is a GUI action, this needs to be possible to be done using code. |
Hello @Kaloszer, as per above failed message
|
No, that seems to be an invalid solution. Unless by design this repository provides invalid .yaml files that cannot be 'more or less' converted to a valid ARM templates. MITRE framework in v11 contains subtechniques Obviously, when you remove the subtechnique, which seems not be supported in the current Microsoft Sentinel solution this will work, that's what I do something for analytic rules pre-deplyoment now to fix this issue. Then you are able to deploy the analytic rule, but that does not explain why there are analytic rules within this repository with an invalid technique. Just look for it: https://github.com/search?q=repo%3AAzure%2FAzure-Sentinel+path%3A*.yaml+.001&type=code
|
Hello @Kaloszer, we are connecting with our concerned team for this issue, once we get any information on this, we will update you. Thanks! |
@Kaloszer, we acknowledge that some of these templates have subtechniques that will cause the deployment to fail. As per discussion with concern team, this is by design and Sentinel currently doesn’t support sub techniques. |
Please reflect this in the docs someplace as this is something that is not defined anywhere, it's misleading. As soon as this is done this matter can be considered closed :) |
Hi @Kaloszer, We are getting in touch with concern team about the documentation. Please expect an update by - 28 Sep. 2023 Thanks! |
Hi @Kaloszer, we connected with concerned team for this issue. They will check on this. Once we get any further information, we will update you. Thanks! |
Hi @Kaloszer, as per discussion with concern team, we are not currently updating the document, but team is considering this fix and will be available in upcoming few months. but with no ETA as of now. |
Describe the bug
Analytic rules with subtechniques fail to deploy:
To Reproduce
Expected behavior
Analytic rule deploys
Screenshots
Additional context
I suspect any and all Analytic Rules that have subtechniques fail to deploy. Using newest api (2023-02-01-preview) yields the same result.
The text was updated successfully, but these errors were encountered: