Open bittib010 opened 11 months ago
Hi @bittib010 , thanks for submitting this!
Currently the resource stores the description in tags
, because it doesn't have a description
property. Do you mean you need the description more than 150 chars? The 150 chars is the limit of the tags
property. You can try split the description into different keys in tags
.
As for the id
property, it is not user configurable, it is generated after the resource creation, it looks like /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/mygroup1/providers/Microsoft.OperationalInsights/workspaces/workspace1/savedSearches/search1
Thank you for replying! So what you are saying is that I have to use tags for the template guid right? Ill try you suggestion on splitting it up. Still I would love to see a focus in the descirption of save searches that deals with the usage of it as hunting ruels in sentinel. Is that doable? :)
Is there any update to my request on updating the information to also mention how to use this as hunting queries?
Is there an existing issue for this?
Community Note
Description
I would love to see a description update to azurerm_log_analytics_saved_search with an added focus on using it as hunting queries for sentinel. We use it a lot, but currently we only use it as a means of what we have learned on behaviors in sentinel and its backend api. Description for the hunting queries are not a variable present we tried using description withing a tags part, but are then limited to 256 characters. Also, how do we determine the template id from community rules? We tried setting "id" as its key with the belonging guid from the rule but get this error: "Error: Invalid or unknown key".
New or Affected Resource(s)/Data Source(s)
azurerm_log_analytics_saved_search
Potential Terraform Configuration
References
No response