-
Notifications
You must be signed in to change notification settings - Fork 82
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Creating Alert rules fails with "suppressionDuration" set #161
Comments
Change to |
That makes no difference. 1H is transformed to PT1H regardless: # Format hour and minute time periods
if ($value -match ".*[HM]") {
return "PT$value"
}
return $value |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hello,
I've noticed that creating a new rule using
New-AzSentinelAlertRule
and setting any value to theSuppressionDuration
parameter, the rule creation fails with the following error:##[error]Unable to initiate class with error: Invalid Properties for Scheduled alert rule: 'suppressionDuration' should be greater than or equal to 'queryFrequency'
I'm using this data to create a rule:
So my parameters are:
I think I have tracked the issue down to this line in
ScheduledAlertProp.ps1
.It seems to use
-ge
to compareQueryFrequency
andSuppressionDuration
. However, running the compare manually gives:This is clearly wrong. There is a workaround though, for now. Specify all times in the same format. So
1H
becomes60M
:The text was updated successfully, but these errors were encountered: