Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.
https://azure.microsoft.com/en-us/services/azure-sentinel/
MIT License
4.39k stars 2.89k forks source link

DCR - Xpath modification trough GUI overwrite previous ARM transformKQL and Output Stream #10678

Open JiTmun opened 2 weeks ago

JiTmun commented 2 weeks ago

Summary Modification of an xpath of a DCR through AZure Monitor overwrite previous dataflows set at DCR creation with an ARM template.

To Reproduce Steps to reproduce the behavior:

  1. Create a DCR from an ARM template with several streams and transformation ARM details: "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0",
  2. deploy to workspace
  3. Go to Azure Monitor on the same DCR,
  4. modify the XPATH only and save
  5. The Output stream is also modified, and dataflows are reset to default

Expected behavior Edit of the Xpath from Azure Monitor should not overwrite dataflows

Screenshots image

If applicable, add screenshots to help explain your problem.

Desktop (please complete the following information):

v-rusraut commented 2 weeks ago

Hi @JiTmun , Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 27 June 2024. Thanks!

v-sudkharat commented 3 days ago

Hi @JiTmun, This Data collection rule issue needs to be investigated by concern (DCR) team, so we kindly request you to raise a support ticket case in azure portal, so our support team can check into it and connect with you if required. Please let us know once you raise a ticket, so we can close this issue from GitHub. Thanks!