Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Bug: Inconsistent parameter when getting entity Host info (MdatpDeviceId vs MdeDeviceId)

Open brolifen opened this issue 3 years ago • 6 comments

Describe the bug When using the "Isolate endpoint - MDE" playbook template some inconsistent data is being sent to the logic app. The data references a parameter which seems to change depending on how the playbook was ran (triggered vs manually).

To Reproduce Steps to reproduce the behavior:

  1. Use the "Isolate endpoint - MDE" playbook template to create a playbook
  2. Setup all the appropriate permissions for the logic app to isolate a device and write comments to the incident
  3. Create an Automation rule with Trigger: "When incident is created" and choose the newly created playbook
  4. Trigger an incident in MDE, wait until it streams to Sentinel.
  5. Notice that the playbook fails because logic app references the "MdatpDeviceId" value which does not exist, instead "MdeDeviceId" was being given in the input.
  6. Now go back to the Incident --> Actions --> Run playbook and choose the same playbook that was triggered automatically
  7. Notice that it now succeeded to run the logic app as now the Entity host info contains "MdatpDeviceId" and no longer "MdeDeviceId".

Expected behavior The deviceId parameter should be either be MdeDeviceId or MdatpDeviceId all the time not change depending on circumstances of running the playbook. It would seem there is some sort of naming migration going on in the backend which breaks this playbook template.

Screenshots SentinelBug

Additional context M365 E5 License

brolifen avatar Dec 07 '22 15:12 brolifen

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Dec 07 '22 15:12 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Dec 07 '22 15:12 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Dec 09 '22 07:12 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Dec 12 '22 09:12 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 04 '23 09:01 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 04 '23 09:01 github-actions[bot]

Hi @brolifen, Thanks for flagging this. There is an open PR with the fix, you can track the status here for the same. Thanks

v-mchatla avatar Jan 23 '23 10:01 v-mchatla

The PR for this fix is merged in master so closing this issue.

v-amolpatil avatar Jan 25 '23 12:01 v-amolpatil

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 25 '23 12:01 github-actions[bot]