Skip to content
This repository was archived by the owner on May 17, 2024. It is now read-only.
This repository was archived by the owner on May 17, 2024. It is now read-only.

Potential api.monitor.azure.com False Positive #427

Open
@0xThiebaut

Description

@0xThiebaut

Microsoft Sentinel relies on api.loganalytics.io, which is the documented API endpoint for Azure's Log Analytics. An example of issued request is the following one:

POST https://api.loganalytics.io/v1/subscriptions/REDACTED/resourceGroups/REDACTED/providers/Microsoft.OperationalInsights/workspaces/REDACTED/metadata?select=categories,solutions,tables,workspaces

The api.loganalytics.io domain is however indirectly blocked as it is a CNAME for api.monitor.azure.com which is on the block-list.

> api.loganalytics.io
Server:  REDACTED
Address:  REDACTED

Name:    api.loganalytics.io
Addresses:  ::
          0.0.0.0

> set type=CNAME
> api.loganalytics.io
Server:  REDACTED
Address:  REDACTED

api.loganalytics.io     canonical name = api.monitor.azure.com

This causes Azure to break.
image

While I have added an exception for it, it might be worth considering whether the api.monitor.azure.com block is intentional.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions