Skip to content

Security insights module New-AzSentinelAlertRule Tactic Parameter wrong Type #21181

Closed
@hiba-farhat

Description

Description

it should be array type not string as we can choose more than one tactic but it's not possible with powershell

Issue script & Debug output

$AnalyticsRulesData = @(
 @{ 
    Enabled = $True
    Query = 'AuditLogs
    | where OperationName =~"Delete conditional access policy"
    | where Result =~ "success"
    | project TimeGenerated, OperationName, policy=TargetResources[0].displayName,modifiedByUpn=InitiatedBy.user.userPrincipalName, modifiedById=InitiatedBy.user.id, result=Result
    | order by TimeGenerated'
    DisplayName = "Conditional Access policy was deleted"
    Description = "Detect when a Conditional Access policy was deleted."
    QueryPeriod = (New-TimeSpan -Hours 1)
    QueryFrequency = (New-TimeSpan -Minutes 5)
    TriggerThreshold = 10
    TriggerOperator = "GreaterThan"
    Severity = "Low"
    Tactic  = @("Initial Access", "Execution", "Persistence")
   }
)

Environment data

Name                           Value
----                           -----
PSVersion                      5.1.18362.1474
PSEdition                      Desktop
PSCompatibleVersions           {1.0, 2.0, 3.0, 4.0...}
BuildVersion                   10.0.18362.1474
CLRVersion                     4.0.30319.42000
WSManStackVersion              3.0
PSRemotingProtocolVersion      2.3
SerializationVersion           1.1.0.1

Module versions

Script     3.0.1      Az.SecurityInsights                 {Get-AzSentinelAlertRule, Get-AzSentinelAlert...
Script     2.2.0      Az.ServiceBus                       {New-AzServiceBusNamespace, Get-AzServiceBusN...

Error output

Cannot process argument transformation on 
parameter 'Tactic'. Cannot convert value to type System.String.

Metadata

Assignees

No one assigned

    Labels

    SecurityInsightsSentinelService AttentionThis issue is responsible by Azure service team.bugThis issue requires a change to an existing behavior in the product in order to be resolved.customer-reported

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions