Skip to content

Commit 3ed5112

Browse files
committed
Sentinel auto gen data connectors refresh Jan 24
1 parent 27f8403 commit 3ed5112

22 files changed

Lines changed: 498 additions & 76 deletions

.openpublishing.redirection.sentinel.json

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -215,11 +215,6 @@
215215
"redirect_url": "/azure/sentinel/data-connectors/rubrik-security-cloud-data-connector-using-azure-functions",
216216
"redirect_document_id": true
217217
},
218-
{
219-
"source_path": "articles/sentinel/data-connectors/cisco-asa-ftd-via-ama.md",
220-
"redirect_url": "/azure/sentinel/data-connectors-reference",
221-
"redirect_document_id": false
222-
},
223218
{
224219
"source_path": "articles/sentinel/data-connectors/okta-single-sign-on-using-azure-function.md",
225220
"redirect_url": "/azure/sentinel/data-connectors/okta-single-sign-on-using-azure-functions",
@@ -484,6 +479,11 @@
484479
"source_path": "articles/sentinel/data-connectors/cyberpion-security-logs.md",
485480
"redirect_url": "/azure/sentinel/data-connectors-reference",
486481
"redirect_document_id": false
487-
}
482+
},
483+
{
484+
"source_path": "articles/sentinel/data-connectors/azure-active-directory-identity-protection.md",
485+
"redirect_url": "/azure/sentinel/data-connectors/microsoft-entra-id-protection",
486+
"redirect_document_id": true
487+
}
488488
]
489489
}

articles/sentinel/TOC.yml

Lines changed: 16 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -372,10 +372,6 @@
372372
href: data-connectors/automated-logic-webctrl.md
373373
- name: Awake Security
374374
href: data-connectors/awake-security.md
375-
- name: Microsoft Entra ID
376-
href: data-connectors/azure-active-directory.md
377-
- name: Microsoft Entra ID Protection
378-
href: data-connectors/azure-active-directory-identity-protection.md
379375
- name: Azure Activity
380376
href: data-connectors/azure-activity.md
381377
- name: Azure Batch Account
@@ -418,6 +414,8 @@
418414
href: data-connectors/cisco-application-centric-infrastructure.md
419415
- name: Cisco ASA
420416
href: data-connectors/cisco-asa.md
417+
- name: Cisco ASA/FTD via AMA (Preview)
418+
href: data-connectors/cisco-asa-ftd-via-ama.md
421419
- name: Cisco Duo Security (using Azure Functions)
422420
href: data-connectors/cisco-duo-security-using-azure-functions.md
423421
- name: Cisco Identity Services Engine
@@ -456,8 +454,12 @@
456454
href: data-connectors/cortex-xdr-incidents.md
457455
- name: Crowdstrike Falcon Data Replicator (using Azure Functions)
458456
href: data-connectors/crowdstrike-falcon-data-replicator-using-azure-functions.md
457+
- name: Crowdstrike Falcon Data Replicator V2 (using Azure Functions)
458+
href: data-connectors/crowdstrike-falcon-data-replicator-v2-using-azure-functions.md
459459
- name: CrowdStrike Falcon Endpoint Protection
460460
href: data-connectors/crowdstrike-falcon-endpoint-protection.md
461+
- name: CyberArk Enterprise Password Vault (EPV) Events
462+
href: data-connectors/cyberark-enterprise-password-vault-epv-events.md
461463
- name: CyberArkEPM (using Azure Functions)
462464
href: data-connectors/cyberarkepm-using-azure-functions.md
463465
- name: Cybersixgill Actionable Alerts (using Azure Functions)
@@ -542,6 +544,8 @@
542544
href: data-connectors/infoblox-nios.md
543545
- name: InfoSecGlobal Data Connector
544546
href: data-connectors/infosecglobal-data-connector.md
547+
- name: IONIX Security Logs
548+
href: data-connectors/ionix-security-logs.md
545549
- name: ISC Bind
546550
href: data-connectors/isc-bind.md
547551
- name: Island Enterprise Browser Admin Audit (Polling CCP)
@@ -594,6 +598,10 @@
594598
href: data-connectors/microsoft-defender-for-office-365.md
595599
- name: Microsoft Defender Threat Intelligence
596600
href: data-connectors/microsoft-defender-threat-intelligence.md
601+
- name: Microsoft Entra ID
602+
href: data-connectors/azure-active-directory.md
603+
- name: Microsoft Entra ID Protection
604+
href: data-connectors/microsoft-entra-id-protection.md
597605
- name: Microsoft Power BI (preview)
598606
href: data-connectors/microsoft-powerbi.md
599607
- name: Microsoft Project (preview)
@@ -680,6 +688,8 @@
680688
href: data-connectors/rsa-securid-authentication-manager.md
681689
- name: Rubrik Security Cloud data connector (using Azure Functions)
682690
href: data-connectors/rubrik-security-cloud-data-connector-using-azure-functions.md
691+
- name: SaaS Security
692+
href: data-connectors/saas-security.md
683693
- name: SailPoint IdentityNow (using Azure Functions)
684694
href: data-connectors/sailpoint-identitynow-using-azure-function.md
685695
- name: Salesforce Service Cloud (using Azure Functions)
@@ -692,6 +702,8 @@
692702
href: data-connectors/senservapro.md
693703
- name: SentinelOne (using Azure Functions)
694704
href: data-connectors/sentinelone-using-azure-functions.md
705+
- name: Seraphic Web Security
706+
href: data-connectors/seraphic-web-security.md
695707
- name: Slack Audit (using Azure Functions)
696708
href: data-connectors/slack-audit-using-azure-functions.md
697709
- name: Snowflake (using Azure Functions)

articles/sentinel/data-connectors-reference.md

Lines changed: 17 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Find your Microsoft Sentinel data connector | Microsoft Docs
33
description: Learn about specific configuration steps for Microsoft Sentinel data connectors.
44
author: cwatson-cat
55
ms.topic: reference
6-
ms.date: 10/23/2023
6+
ms.date: 07/26/2023
77
ms.author: cwatson
88
---
99

@@ -123,6 +123,7 @@ Data connectors are available as part of the following offerings:
123123
- [[Recommended] Cisco Secure Email Gateway via AMA](data-connectors/recommended-cisco-secure-email-gateway-via-ama.md)
124124
- [Cisco Application Centric Infrastructure](data-connectors/cisco-application-centric-infrastructure.md)
125125
- [Cisco ASA](data-connectors/cisco-asa.md)
126+
- [Cisco ASA/FTD via AMA (Preview)](data-connectors/cisco-asa-ftd-via-ama.md)
126127
- [Cisco Duo Security (using Azure Functions)](data-connectors/cisco-duo-security-using-azure-functions.md)
127128
- [Cisco Identity Services Engine](data-connectors/cisco-identity-services-engine.md)
128129
- [Cisco Meraki](data-connectors/cisco-meraki.md)
@@ -173,6 +174,7 @@ Data connectors are available as part of the following offerings:
173174
## Crowdstrike
174175

175176
- [Crowdstrike Falcon Data Replicator (using Azure Functions)](data-connectors/crowdstrike-falcon-data-replicator-using-azure-functions.md)
177+
- [Crowdstrike Falcon Data Replicator V2 (using Azure Functions) (Preview)](data-connectors/crowdstrike-falcon-data-replicator-v2-using-azure-functions.md)
176178
- [CrowdStrike Falcon Endpoint Protection](data-connectors/crowdstrike-falcon-endpoint-protection.md)
177179

178180
## Cyber Defense Group B.V.
@@ -184,6 +186,10 @@ Data connectors are available as part of the following offerings:
184186
- [CyberArk Enterprise Password Vault (EPV) Events](data-connectors/cyberark-enterprise-password-vault-epv-events.md)
185187
- [CyberArkEPM (using Azure Functions)](data-connectors/cyberarkepm-using-azure-functions.md)
186188

189+
## CyberPion
190+
191+
- [IONIX Security Logs](data-connectors/ionix-security-logs.md)
192+
187193
## Cybersixgill
188194

189195
- [Cybersixgill Actionable Alerts (using Azure Functions)](data-connectors/cybersixgill-actionable-alerts-using-azure-functions.md)
@@ -390,11 +396,9 @@ Data connectors are available as part of the following offerings:
390396
## Microsoft
391397

392398
- [Automated Logic WebCTRL](data-connectors/automated-logic-webctrl.md)
393-
- [Microsoft Entra ID](data-connectors/azure-active-directory.md)
394-
- [Microsoft Entra ID Protection](data-connectors/azure-active-directory-identity-protection.md)
395399
- [Azure Activity](data-connectors/azure-activity.md)
396400
- [Azure Batch Account](data-connectors/azure-batch-account.md)
397-
- [Azure AI Search](data-connectors/azure-cognitive-search.md)
401+
- [Azure Cognitive Search](data-connectors/azure-cognitive-search.md)
398402
- [Azure Data Lake Storage Gen1](data-connectors/azure-data-lake-storage-gen1.md)
399403
- [Azure DDoS Protection](data-connectors/azure-ddos-protection.md)
400404
- [Azure Event Hub](data-connectors/azure-event-hub.md)
@@ -419,6 +423,8 @@ Data connectors are available as part of the following offerings:
419423
- [Microsoft Defender for IoT](data-connectors/microsoft-defender-for-iot.md)
420424
- [Microsoft Defender for Office 365 (preview)](data-connectors/microsoft-defender-for-office-365.md)
421425
- [Microsoft Defender Threat Intelligence](data-connectors/microsoft-defender-threat-intelligence.md)
426+
- [Microsoft Entra ID](data-connectors/azure-active-directory.md)
427+
- [Microsoft Entra ID Protection](data-connectors/microsoft-entra-id-protection.md)
422428
- [Microsoft PowerBI (preview)](data-connectors/microsoft-powerbi.md)
423429
- [Microsoft Project (preview)](data-connectors/microsoft-project.md)
424430
- [Microsoft Purview (preview)](data-connectors/microsoft-purview.md)
@@ -611,6 +617,9 @@ Data connectors are available as part of the following offerings:
611617

612618
- [SentinelOne (using Azure Functions)](data-connectors/sentinelone-using-azure-functions.md)
613619

620+
## SERAPHIC ALGORITHMS LTD
621+
- [Seraphic Web Security](data-connectors/seraphic-web-security.md)
622+
614623
## Slack
615624

616625
- [Slack Audit (using Azure Functions)](data-connectors/slack-audit-using-azure-functions.md)
@@ -679,6 +688,10 @@ Data connectors are available as part of the following offerings:
679688

680689
- [Ubiquiti UniFi (Preview)](data-connectors/ubiquiti-unifi.md)
681690

691+
## Valence Security Inc.
692+
693+
- [SaaS Security](data-connectors/saas-security.md)
694+
682695
## vArmour Networks
683696

684697
- [vArmour Application Controller](data-connectors/varmour-application-controller.md)

articles/sentinel/data-connectors/armorblox-using-azure-functions.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: "Armorblox (using Azure Functions) connector for Microsoft Sentinel"
33
description: "Learn how to install the connector Armorblox (using Azure Functions) to connect your data source to Microsoft Sentinel."
44
author: cwatson-cat
55
ms.topic: how-to
6-
ms.date: 07/26/2023
6+
ms.date: 01/06/2024
77
ms.service: microsoft-sentinel
88
ms.author: cwatson
99
---
@@ -20,7 +20,7 @@ The [Armorblox](https://www.armorblox.com/) data connector provides the capabili
2020
| **Azure function app code** | https://aka.ms/sentinel-armorblox-functionapp |
2121
| **Log Analytics table(s)** | Armorblox_CL<br/> |
2222
| **Data collection rules support** | Not currently supported |
23-
| **Supported by** | [armorblox](https://www.armorblox.com/contact/) |
23+
| **Supported by** | [Armorblox](https://www.armorblox.com/contact/) |
2424

2525
## Query samples
2626

articles/sentinel/data-connectors/blackberry-cylanceprotect.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: "Blackberry CylancePROTECT connector for Microsoft Sentinel"
33
description: "Learn how to install the connector Blackberry CylancePROTECT to connect your data source to Microsoft Sentinel."
44
author: cwatson-cat
55
ms.topic: how-to
6-
ms.date: 03/25/2023
6+
ms.date: 01/06/2024
77
ms.service: microsoft-sentinel
88
ms.author: cwatson
99
---
@@ -76,7 +76,7 @@ Configure the facilities you want to collect and their severities.
7676

7777
3. Configure and connect the CylancePROTECT
7878

79-
Use the IP address or hostname for the Linux device with the Linux agent installed as the Destination IP address.
79+
[Follow these instructions](https://docs.blackberry.com/content/dam/docs-blackberry-com/release-pdfs/en/cylance-products/syslog-guides/Cylance%20Syslog%20Guide%20v2.0%20rev12.pdf) to configure the CylancePROTECT to forward syslog. Use the IP address or hostname for the Linux device with the Linux agent installed as the Destination IP address.
8080

8181

8282

Lines changed: 63 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,63 @@
1+
---
2+
title: "Cisco ASA/FTD via AMA (Preview) connector for Microsoft Sentinel"
3+
description: "Learn how to install the connector Cisco ASA/FTD via AMA (Preview) to connect your data source to Microsoft Sentinel."
4+
author: cwatson-cat
5+
ms.topic: how-to
6+
ms.date: 01/06/2024
7+
ms.service: microsoft-sentinel
8+
ms.author: cwatson
9+
---
10+
11+
# Cisco ASA/FTD via AMA (Preview) connector for Microsoft Sentinel
12+
13+
The Cisco ASA firewall connector allows you to easily connect your Cisco ASA logs with Microsoft Sentinel, to view dashboards, create custom alerts, and improve investigation. This gives you more insight into your organization's network and improves your security operation capabilities.
14+
15+
## Connector attributes
16+
17+
| Connector attribute | Description |
18+
| --- | --- |
19+
| **Log Analytics table(s)** | CommonSecurityLog<br/> |
20+
| **Data collection rules support** | [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal) |
21+
| **Supported by** | [Microsoft Corporation](https://support.microsoft.com/) |
22+
23+
## Query samples
24+
25+
**All logs**
26+
```kusto
27+
CommonSecurityLog
28+
29+
| where DeviceVendor == "Cisco"
30+
31+
| where DeviceProduct == "ASA"
32+
33+
| sort by TimeGenerated
34+
```
35+
36+
37+
38+
## Prerequisites
39+
40+
To integrate with Cisco ASA/FTD via AMA (Preview) make sure you have:
41+
42+
- To collect data from non-Azure VMs, they must have Azure Arc installed and enabled. [Learn more](/azure/azure-monitor/agents/azure-monitor-agent-install?tabs=ARMAgentPowerShell,PowerShellWindows,PowerShellWindowsArc,CLIWindows,CLIWindowsArc)
43+
44+
45+
## Vendor installation instructions
46+
47+
Enable data collection rule​
48+
49+
Cisco ASA/FTD event logs are collected only from **Linux** agents.
50+
51+
52+
53+
54+
Run the following command to install and apply the Cisco ASA/FTD collector:
55+
56+
57+
`sudo wget -O Forwarder_AMA_installer.py https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/DataConnectors/Syslog/Forwarder_AMA_installer.py&&sudo python Forwarder_AMA_installer.py`
58+
59+
60+
61+
## Next steps
62+
63+
For more information, go to the [related solution](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/azuresentinel.azure-sentinel-solution-ciscoasa?tab=Overview) in the Azure Marketplace.

articles/sentinel/data-connectors/cisco-stealthwatch.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,21 +3,21 @@ title: "Cisco Stealthwatch connector for Microsoft Sentinel"
33
description: "Learn how to install the connector Cisco Stealthwatch to connect your data source to Microsoft Sentinel."
44
author: cwatson-cat
55
ms.topic: how-to
6-
ms.date: 02/23/2023
6+
ms.date: 01/06/2024
77
ms.service: microsoft-sentinel
88
ms.author: cwatson
99
---
1010

1111
# Cisco Stealthwatch connector for Microsoft Sentinel
1212

13-
The [Cisco Stealthwatch](https://www.cisco.com/c/en/us/products/security/stealthwatch/index.html) data connector provides the capability to ingest [Cisco Stealthwatch events](https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/management_console/securit_events_alarm_categories/SW_7_2_1_Security_Events_and_Alarm_Categories_DV_1_0.pdf) into Microsoft Sentinel.
13+
The [Cisco Stealthwatch](https://www.cisco.com/c/en/us/products/security/stealthwatch/index.html) data connector provides the capability to ingest [Cisco Stealthwatch events](https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/management_console/securit_events_alarm_categories/SW_7_2_1_Security_Events_and_Alarm_Categories_DV_1_0.pdf) into Microsoft Sentinel. Refer to [Cisco Stealthwatch documentation](https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/system_installation_configuration/SW_7_3_2_System_Configuration_Guide_DV_1_0.pdf) for more information.
1414

1515
## Connector attributes
1616

1717
| Connector attribute | Description |
1818
| --- | --- |
1919
| **Log Analytics table(s)** | Syslog (StealthwatchEvent)<br/> |
20-
| **Data collection rules support** | [Workspace transform DCR](../../azure-monitor/logs/tutorial-workspace-transformations-portal.md) |
20+
| **Data collection rules support** | [Workspace transform DCR](/azure/azure-monitor/logs/tutorial-workspace-transformations-portal) |
2121
| **Supported by** | [Microsoft Corporation](https://support.microsoft.com) |
2222

2323
## Query samples

0 commit comments

Comments
 (0)