lightswitch05 / hosts

Hostfile blocklist for ads and tracking, updated regularly
https://www.github.developerdan.com/hosts/
Apache License 2.0
1.5k stars 75 forks source link

Potential `api.monitor.azure.com` False Positive #427

Open 0xThiebaut opened 5 months ago

0xThiebaut commented 5 months ago

Microsoft Sentinel relies on api.loganalytics.io, which is the documented API endpoint for Azure's Log Analytics. An example of issued request is the following one:

POST https://api.loganalytics.io/v1/subscriptions/REDACTED/resourceGroups/REDACTED/providers/Microsoft.OperationalInsights/workspaces/REDACTED/metadata?select=categories,solutions,tables,workspaces

The api.loganalytics.io domain is however indirectly blocked as it is a CNAME for api.monitor.azure.com which is on the block-list.

> api.loganalytics.io
Server:  REDACTED
Address:  REDACTED

Name:    api.loganalytics.io
Addresses:  ::
          0.0.0.0

> set type=CNAME
> api.loganalytics.io
Server:  REDACTED
Address:  REDACTED

api.loganalytics.io     canonical name = api.monitor.azure.com

This causes Azure to break. image

While I have added an exception for it, it might be worth considering whether the api.monitor.azure.com block is intentional.