diff --git a/Solutions/Web Session Essentials/Data/Solution_Web Session Essentials.json b/Solutions/Web Session Essentials/Data/Solution_Web Session Essentials.json index 3c6b4e04fff..18b361bf035 100644 --- a/Solutions/Web Session Essentials/Data/Solution_Web Session Essentials.json +++ b/Solutions/Web Session Essentials/Data/Solution_Web Session Essentials.json @@ -2,7 +2,7 @@ "Name": "Web Session Essentials", "Author": "Microsoft - support@microsoft.com", "Logo": "", - "Description": "Web Session Essentials is a [domain solution](https://learn.microsoft.com/azure/sentinel/sentinel-solutions-catalog#domain-solutions) and does not include any data connectors. The content in this solution requires one of the product solutions below, as well as any other connector or data source normalized to the [ASIM](https://aka.ms/AboutASIM).\n\n**Prerequisite :-**\n\n Install one or more of the listed solutions, or develop your custom ASIM parsers to unlock the value provided by this solution.\n 1. Palo Alto PAN-OS \n 2. SquidProxy \n 3. Vectra AI Stream \n 4. Zscaler Internet Access \n 5. IIS logs (via LA agent) \n\n**Underlying Microsoft Technologies used:** \n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n 1. Product solutions as described above \n 2. Logic app for data summarization\n\n**Recommendation :-**\n\nIt is highly recommended to use the **SummarizeWebSessionData** logic app playbook provided with this solution as it will significantly improve the performance of the Workbook, Analytic rules & Hunting queries.", + "Description": "Web Session Essentials is a [domain solution](https://learn.microsoft.com/azure/sentinel/sentinel-solutions-catalog#domain-solutions) and does not include any data connectors. The content in this solution requires one of the product solutions below, as well as any other connector or data source normalized to the [ASIM](https://aka.ms/AboutASIM).\n\n**Prerequisite :-**\n\n Install one or more of the listed solutions, or develop your custom ASIM parsers to unlock the value provided by this solution.\n 1. Palo Alto PAN-OS \n 2. SquidProxy \n 3. Vectra AI Stream \n 4. Zscaler Internet Access \n 5. IIS logs (via LA agent) \n\n**Underlying Microsoft Technologies used:** \n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n 1. Product solutions as described above \n 2. Logic app for data summarization\n\n**Recommendation :-**\n\nIt is highly recommended to use the **SummarizeWebSessionData** logic app playbook provided with this solution as it will significantly improve the performance of the Workbook, Analytic rules & Hunting queries.\n **NOTE: This solution includes the playbook SummarizeWebSessionData, which uses the legacy HTTP data collector API to ingest data. Since that API is about to be deprecated, we recommend using the SummarizeWebSessionData_logingestion playbook instead.**", "Workbooks": [ "Workbooks/WebSessionEssentials.json" ], @@ -35,7 +35,8 @@ "Hunting Queries/ThreatInfoFoundInWebRequests.yaml" ], "Playbooks": [ - "Playbooks/SummarizeWebSessionData/azuredeploy.json" + "Playbooks/SummarizeWebSessionData/azuredeploy.json", + "Playbooks/SummarizeWebSessionData_logingestion/azuredeploy.json" ], "dependentDomainSolutionIds": [ "azuresentinel.azure-sentinel-solution-paloaltopanos", @@ -44,7 +45,7 @@ "zscaler1579058425289.zscaler_internet_access_mss" ], "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Web Session Essentials\\", - "Version": "3.0.3", + "Version": "3.0.4", "TemplateSpec": true, "Metadata": "SolutionMetadata.json" } \ No newline at end of file diff --git a/Solutions/Web Session Essentials/Package/3.0.4.zip b/Solutions/Web Session Essentials/Package/3.0.4.zip new file mode 100644 index 00000000000..a4ca63f948e Binary files /dev/null and b/Solutions/Web Session Essentials/Package/3.0.4.zip differ diff --git a/Solutions/Web Session Essentials/Package/createUiDefinition.json b/Solutions/Web Session Essentials/Package/createUiDefinition.json index b5369c9165d..f50274c1c65 100644 --- a/Solutions/Web Session Essentials/Package/createUiDefinition.json +++ b/Solutions/Web Session Essentials/Package/createUiDefinition.json @@ -6,7 +6,7 @@ "config": { "isWizard": false, "basics": { - "description": "\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Web%20Session%20Essentials/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nWeb Session Essentials is a [domain solution](https://learn.microsoft.com/azure/sentinel/sentinel-solutions-catalog#domain-solutions) and does not include any data connectors. The content in this solution requires one of the product solutions below, as well as any other connector or data source normalized to the [ASIM](https://aka.ms/AboutASIM).\n\n**Prerequisite :-**\n\n Install one or more of the listed solutions, or develop your custom ASIM parsers to unlock the value provided by this solution.\n 1. Palo Alto PAN-OS \n 2. SquidProxy \n 3. Vectra AI Stream \n 4. Zscaler Internet Access \n 5. IIS logs (via LA agent) \n\n**Underlying Microsoft Technologies used:** \n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n 1. Product solutions as described above \n 2. Logic app for data summarization\n\n**Recommendation :-**\n\nIt is highly recommended to use the **SummarizeWebSessionData** logic app playbook provided with this solution as it will significantly improve the performance of the Workbook, Analytic rules & Hunting queries.\n\n**Workbooks:** 1, **Analytic Rules:** 15, **Hunting Queries:** 9, **Playbooks:** 1\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", + "description": "\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Web%20Session%20Essentials/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nWeb Session Essentials is a [domain solution](https://learn.microsoft.com/azure/sentinel/sentinel-solutions-catalog#domain-solutions) and does not include any data connectors. The content in this solution requires one of the product solutions below, as well as any other connector or data source normalized to the [ASIM](https://aka.ms/AboutASIM).\n\n**Prerequisite :-**\n\n Install one or more of the listed solutions, or develop your custom ASIM parsers to unlock the value provided by this solution.\n 1. Palo Alto PAN-OS \n 2. SquidProxy \n 3. Vectra AI Stream \n 4. Zscaler Internet Access \n 5. IIS logs (via LA agent) \n\n**Underlying Microsoft Technologies used:** \n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n 1. Product solutions as described above \n 2. Logic app for data summarization\n\n**Recommendation :-**\n\nIt is highly recommended to use the **SummarizeWebSessionData** logic app playbook provided with this solution as it will significantly improve the performance of the Workbook, Analytic rules & Hunting queries.\n **NOTE: This solution includes the playbook SummarizeWebSessionData, which uses the legacy HTTP data collector API to ingest data. Since that API is about to be deprecated, we recommend using the SummarizeWebSessionData_logingestion playbook instead.**\n\n**Workbooks:** 1, **Analytic Rules:** 15, **Hunting Queries:** 9, **Playbooks:** 2\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", "subscription": { "resourceProviders": [ "Microsoft.OperationsManagement/solutions", diff --git a/Solutions/Web Session Essentials/Package/mainTemplate.json b/Solutions/Web Session Essentials/Package/mainTemplate.json index 8cb84e79b1a..ab7f480005e 100644 --- a/Solutions/Web Session Essentials/Package/mainTemplate.json +++ b/Solutions/Web Session Essentials/Package/mainTemplate.json @@ -41,7 +41,7 @@ "email": "support@microsoft.com", "_email": "[variables('email')]", "_solutionName": "Web Session Essentials", - "_solutionVersion": "3.0.3", + "_solutionVersion": "3.0.4", "solutionId": "azuresentinel.azure-sentinel-solution-websession-domain", "_solutionId": "[variables('solutionId')]", "workbookVersion1": "1.0.0", @@ -51,7 +51,7 @@ "_workbookContentId1": "[variables('workbookContentId1')]", "workspaceResourceId": "[resourceId('microsoft.OperationalInsights/Workspaces', parameters('workspace'))]", "_workbookcontentProductId1": "[concat(take(variables('_solutionId'),50),'-','wb','-', uniqueString(concat(variables('_solutionId'),'-','Workbook','-',variables('_workbookContentId1'),'-', variables('workbookVersion1'))))]", - "TemplateEmptyArray": "[json('[]')]", + "TemplateEmptyArray": "[json('[]')]", "analyticRuleObject1": { "analyticRuleVersion1": "1.0.1", "_analyticRulecontentId1": "32c08696-2e37-4730-86f8-97d9c8b184c9", @@ -211,6 +211,14 @@ "playbookTemplateSpecName1": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat(parameters('workspace'),'-pl-',uniquestring(variables('_playbookContentId1'))))]", "_playbookcontentProductId1": "[concat(take(variables('_solutionId'),50),'-','pl','-', uniqueString(concat(variables('_solutionId'),'-','Playbook','-',variables('_playbookContentId1'),'-', variables('playbookVersion1'))))]", "blanks": "[replace('b', 'b', '')]", + "SummarizeWebSessionData_logingestion": "SummarizeWebSessionData_logingestion", + "_SummarizeWebSessionData_logingestion": "[variables('SummarizeWebSessionData_logingestion')]", + "playbookVersion2": "1.0", + "playbookContentId2": "SummarizeWebSessionData_logingestion", + "_playbookContentId2": "[variables('playbookContentId2')]", + "playbookId2": "[resourceId('Microsoft.Logic/workflows', variables('playbookContentId2'))]", + "playbookTemplateSpecName2": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat(parameters('workspace'),'-pl-',uniquestring(variables('_playbookContentId2'))))]", + "_playbookcontentProductId2": "[concat(take(variables('_solutionId'),50),'-','pl','-', uniqueString(concat(variables('_solutionId'),'-','Playbook','-',variables('_playbookContentId2'),'-', variables('playbookVersion2'))))]", "_solutioncontentProductId": "[concat(take(variables('_solutionId'),50),'-','sl','-', uniqueString(concat(variables('_solutionId'),'-','Solution','-',variables('_solutionId'),'-', variables('_solutionVersion'))))]" }, "resources": [ @@ -223,7 +231,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "WebSessionEssentials Workbook with template version 3.0.3", + "description": "WebSessionEssentials Workbook with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('workbookVersion1')]", @@ -298,7 +306,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "CommandInURL_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "CommandInURL_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject1').analyticRuleVersion1]", @@ -336,58 +344,58 @@ ], "entityMappings": [ { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "DstIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "DstIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "URL", "fieldMappings": [ { - "columnName": "Url", - "identifier": "Url" + "identifier": "Url", + "columnName": "Url" } - ], - "entityType": "URL" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "SrcUsername", - "identifier": "FullName" + "identifier": "FullName", + "columnName": "SrcUsername" }, { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { - "EventStartTime": "EventStartTime", - "Decoded_url": "Decoded_url", "EventEndTime": "EventEndTime", - "EventCount": "EventCount" + "Decoded_url": "Decoded_url", + "EventCount": "EventCount", + "EventStartTime": "EventStartTime" }, "alertDetailsOverride": { "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP '{{SrcIpAddr}}' has been identified as making request for URL '{{Url}}' that includes a recognizable malicious command" @@ -445,7 +453,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DataExfiltrationTimeSeriesAnomaly_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "DataExfiltrationTimeSeriesAnomaly_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject2').analyticRuleVersion2]", @@ -471,7 +479,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "Exfiltration" ], @@ -480,31 +488,31 @@ ], "entityMappings": [ { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SourceIP", - "identifier": "Address" + "identifier": "Address", + "columnName": "SourceIP" } - ], - "entityType": "IP" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { - "DestinationIPList": "DestinationIPList", - "anomalies": "anomalies", + "DestinationPortList": "DestinationPortList", "SourceIPList": "SourceIPList", - "ReceivedBytesinMB": "ReceivedBytesinMB", + "anomalies": "anomalies", "SentBytesinMB": "SentBytesinMB", - "DestinationPortList": "DestinationPortList", - "score": "score", - "EventCount": "EventCount" + "EventCount": "EventCount", + "ReceivedBytesinMB": "ReceivedBytesinMB", + "DestinationIPList": "DestinationIPList", + "score": "score" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "IP address '{{SourceIP}}' is engaged in data transfers to a public network that exceeds usual levels", - "alertDescriptionFormat": "Please conduct a thorough investigation of each IPAddresses listed in SourceIPList: '{{SourceIPList}}' to identify any suspicious activities that may require further investigation. 'SourceIPList' include the top 10 client IP addresses that transmitted the highest amount of data during the anomalous hour" + "alertDescriptionFormat": "Please conduct a thorough investigation of each IPAddresses listed in SourceIPList: '{{SourceIPList}}' to identify any suspicious activities that may require further investigation. 'SourceIPList' include the top 10 client IP addresses that transmitted the highest amount of data during the anomalous hour", + "alertDisplayNameFormat": "IP address '{{SourceIP}}' is engaged in data transfers to a public network that exceeds usual levels" } } }, @@ -559,7 +567,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "DiscordCDNRiskyFileDownload_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "DiscordCDNRiskyFileDownload_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject3').analyticRuleVersion3]", @@ -585,7 +593,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "CommandAndControl" ], @@ -597,44 +605,44 @@ ], "entityMappings": [ { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "URL", "fieldMappings": [ { - "columnName": "Url", - "identifier": "Url" + "identifier": "Url", + "columnName": "Url" } - ], - "entityType": "URL" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] } ], "eventGroupingSettings": { @@ -645,8 +653,8 @@ "EventStartTime": "EventStartTime" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "User '{{SrcUsername}}' with the IP address '{{SrcIpAddr}}' has been detected downloading potentially risky files from the Discord CDN", - "alertDescriptionFormat": " Client requested for URL '{{Url}}' that contains a files hosted on a recognized Discord Content Delivery Network (CDN) which are considered to be potentially risky. It is essential to investigate further to determine the nature of the files being requested and the intent of the users involved" + "alertDescriptionFormat": " Client requested for URL '{{Url}}' that contains a files hosted on a recognized Discord Content Delivery Network (CDN) which are considered to be potentially risky. It is essential to investigate further to determine the nature of the files being requested and the intent of the users involved", + "alertDisplayNameFormat": "User '{{SrcUsername}}' with the IP address '{{SrcIpAddr}}' has been detected downloading potentially risky files from the Discord CDN" } } }, @@ -701,7 +709,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "KnownMaliciousUserAgents_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "KnownMaliciousUserAgents_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject4').analyticRuleVersion4]", @@ -727,7 +735,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "InitialAccess", "CommandAndControl" @@ -739,68 +747,68 @@ ], "entityMappings": [ { + "entityType": "URL", "fieldMappings": [ { - "columnName": "Url", - "identifier": "Url" + "identifier": "Url", + "columnName": "Url" } - ], - "entityType": "URL" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "DstIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "DstIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { - "EventStartTime": "EventStartTime", - "EventCount": "EventCount", "EventEndTime": "EventEndTime", "UserAgentCategory": "UserAgentCategory", - "HttpUserAgent": "HttpUserAgent" + "HttpUserAgent": "HttpUserAgent", + "EventStartTime": "EventStartTime", + "EventCount": "EventCount" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP '{{SrcIpAddr}}' has been observed using User Agent categorized as '{{UserAgentCategory}}'", - "alertDescriptionFormat": "User accessed this URL '{{Url}}' using User Agent '{{HttpUserAgent}}'. Perform a thorough analysis of the requests associated with this user agent header" + "alertDescriptionFormat": "User accessed this URL '{{Url}}' using User Agent '{{HttpUserAgent}}'. Perform a thorough analysis of the requests associated with this user agent header", + "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP '{{SrcIpAddr}}' has been observed using User Agent categorized as '{{UserAgentCategory}}'" } } }, @@ -855,7 +863,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "LocalFileInclusion-LFI_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "LocalFileInclusion-LFI_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject5').analyticRuleVersion5]", @@ -881,7 +889,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "InitialAccess", "Execution" @@ -893,58 +901,58 @@ ], "entityMappings": [ { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "URL", "fieldMappings": [ { - "columnName": "Url", - "identifier": "Url" + "identifier": "Url", + "columnName": "Url" } - ], - "entityType": "URL" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { - "EventStartTime": "EventStartTime", - "Decoded_url": "Decoded_url", "EventEndTime": "EventEndTime", - "EventCount": "EventCount" + "Decoded_url": "Decoded_url", + "EventCount": "EventCount", + "EventStartTime": "EventStartTime" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "Potential Local File Inlcusion(LFI) performed by user '{{SrcUsername}}' from IP '{{SrcIpAddr}}'", - "alertDescriptionFormat": "User requested for URL '{{Url}}' which contains LFI related keywords or indicators. It suggests an attempt to traverse directories and access files outside the intended directory structure" + "alertDescriptionFormat": "User requested for URL '{{Url}}' which contains LFI related keywords or indicators. It suggests an attempt to traverse directories and access files outside the intended directory structure", + "alertDisplayNameFormat": "Potential Local File Inlcusion(LFI) performed by user '{{SrcUsername}}' from IP '{{SrcIpAddr}}'" } } }, @@ -999,7 +1007,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MultipleClientErrorsWithinShortTime_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "MultipleClientErrorsWithinShortTime_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject6').analyticRuleVersion6]", @@ -1025,7 +1033,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "InitialAccess", "CommandAndControl" @@ -1037,51 +1045,51 @@ ], "entityMappings": [ { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { - "EventStartTime": "EventStartTime", + "RequestURLs": "URLs", "TotalErrorCount": "TotalErrorCount", - "ErrorThreshold": "Threshold", - "EventEndTime": "EventEndTime", + "EventStartTime": "EventStartTime", "EventResultSet": "EventResultDetailsSet", - "RequestURLs": "URLs" + "ErrorThreshold": "Threshold", + "EventEndTime": "EventEndTime" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "High number of client errors originated by user '{{SrcUsername}}' from IP address '{{SrcIpAddr}}'", - "alertDescriptionFormat": "The client has made a total of '{{TotalErrorCount}}' requests to URLs '{{URLs}}', which have resulted in client errors. A sudden surge in HTTP code errors, especially in the form of client-side errors like 400 or 401, could indicate malicious activity, such as attackers attempting to exploit vulnerabilities or perform unauthorized actions. For detailed information regarding the specific errors encountered, please refer to the following link: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status." + "alertDescriptionFormat": "The client has made a total of '{{TotalErrorCount}}' requests to URLs '{{URLs}}', which have resulted in client errors. A sudden surge in HTTP code errors, especially in the form of client-side errors like 400 or 401, could indicate malicious activity, such as attackers attempting to exploit vulnerabilities or perform unauthorized actions. For detailed information regarding the specific errors encountered, please refer to the following link: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status.", + "alertDisplayNameFormat": "High number of client errors originated by user '{{SrcUsername}}' from IP address '{{SrcIpAddr}}'" } } }, @@ -1136,7 +1144,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MultipleServerErrorsWithinShortTime_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "MultipleServerErrorsWithinShortTime_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject7').analyticRuleVersion7]", @@ -1162,7 +1170,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "InitialAccess", "Impact" @@ -1174,51 +1182,51 @@ ], "entityMappings": [ { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { - "EventStartTime": "EventStartTime", + "RequestURLs": "URLs", "TotalErrorCount": "TotalErrorCount", - "ErrorThreshold": "Threshold", - "EventEndTime": "EventEndTime", + "EventStartTime": "EventStartTime", "EventResultSet": "EventResultDetailsSet", - "RequestURLs": "URLs" + "ErrorThreshold": "Threshold", + "EventEndTime": "EventEndTime" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "High number of server errors originated by user '{{SrcUsername}}' from IP address '{{SrcIpAddr}}'", - "alertDescriptionFormat": "The client has made a total of '{{TotalErrorCount}}' requests to URLs '{{URLs}}', which have resulted in server errors. It is recommended to thoroughly investigate this alert to determine the underlying cause behind this significant number of errors. For detailed information regarding the specific errors encountered, please refer to the following link: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status." + "alertDescriptionFormat": "The client has made a total of '{{TotalErrorCount}}' requests to URLs '{{URLs}}', which have resulted in server errors. It is recommended to thoroughly investigate this alert to determine the underlying cause behind this significant number of errors. For detailed information regarding the specific errors encountered, please refer to the following link: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status.", + "alertDisplayNameFormat": "High number of server errors originated by user '{{SrcUsername}}' from IP address '{{SrcIpAddr}}'" } } }, @@ -1273,7 +1281,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "MultipleUAsFromSingleIP_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "MultipleUAsFromSingleIP_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject8').analyticRuleVersion8]", @@ -1299,7 +1307,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "InitialAccess", "CredentialAccess" @@ -1311,35 +1319,35 @@ ], "entityMappings": [ { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] } ], "eventGroupingSettings": { @@ -1348,13 +1356,13 @@ "customDetails": { "UserAgentThreshold": "Threshold", "UserAgentArray": "UserAgentList", - "UserAgentCount": "UserAgentCount", "DestinationIPList": "DestinationIPList", - "URLs": "URL_List" + "URLs": "URL_List", + "UserAgentCount": "UserAgentCount" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP '{{SrcIpAddr}}' has been observed using high number of User Agents within short timeframe", - "alertDescriptionFormat": "The system has detected high User Agent count of '{{UserAgentCount}}' originating from '{{SrcUsername}}'. Further investigation is necessary to determine the reason behind the detection of multiple user agents associated with the SrcIpAddr in this incident. User Agent list include: '{{UserAgentList}}'" + "alertDescriptionFormat": "The system has detected high User Agent count of '{{UserAgentCount}}' originating from '{{SrcUsername}}'. Further investigation is necessary to determine the reason behind the detection of multiple user agents associated with the SrcIpAddr in this incident. User Agent list include: '{{UserAgentList}}'", + "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP '{{SrcIpAddr}}' has been observed using high number of User Agents within short timeframe" } } }, @@ -1409,7 +1417,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PossibleMaliciousDoubleExtension_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "PossibleMaliciousDoubleExtension_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject9').analyticRuleVersion9]", @@ -1435,7 +1443,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "DefenseEvasion", "Persistence", @@ -1448,67 +1456,67 @@ ], "entityMappings": [ { + "entityType": "File", "fieldMappings": [ { - "columnName": "FileWithdualextension", - "identifier": "Name" + "identifier": "Name", + "columnName": "FileWithdualextension" } - ], - "entityType": "File" + ] }, { + "entityType": "URL", "fieldMappings": [ { - "columnName": "Url", - "identifier": "Url" + "identifier": "Url", + "columnName": "Url" } - ], - "entityType": "URL" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { - "EventStartTime": "EventStartTime", - "EventCount": "EventCount", "EventEndTime": "EventEndTime", - "DstHostname": "DstHostname" + "DstHostname": "DstHostname", + "EventStartTime": "EventStartTime", + "EventCount": "EventCount" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP address '{{SrcIpAddr}}' has been observed with posting potentially risky dual extension file", - "alertDescriptionFormat": "User posted file '{{FileWithdualextension}}' which potentially contain dual extensions. This type of activity could be malicious and performed to bypass file upload filters or security measures implemented by the application. Destination server name this request was targetted to - '{{DstHostname}}'" + "alertDescriptionFormat": "User posted file '{{FileWithdualextension}}' which potentially contain dual extensions. This type of activity could be malicious and performed to bypass file upload filters or security measures implemented by the application. Destination server name this request was targetted to - '{{DstHostname}}'", + "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP address '{{SrcIpAddr}}' has been observed with posting potentially risky dual extension file" } } }, @@ -1563,7 +1571,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PotentionalFileEnumeration_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "PotentionalFileEnumeration_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject10').analyticRuleVersion10]", @@ -1589,7 +1597,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "Discovery", "CommandAndControl", @@ -1602,60 +1610,60 @@ ], "entityMappings": [ { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "DstHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "DstHostname" } - ], - "entityType": "Host" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { + "RequestCount": "RequestCount", + "RequestURLs": "RequestURLs", + "FileCount": "FileCount", "EventStartTime": "EventStartTime", "DestinationIPList": "DestinationIPList", - "FileCount": "FileCount", - "RequestCount": "RequestCount", - "EventEndTime": "EventEndTime", - "RequestURLs": "RequestURLs" + "EventEndTime": "EventEndTime" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP '{{SrcIpAddr}}' has been observed with performing file enumeration activity", - "alertDescriptionFormat": "User generated multiple requests '{{RequestCount}}' that has resulted in error code '404', suggesting the possibility of file enumeration activity. It's important to investigate the source and patterns of these extensive 404 errors to identify potential security threats. Details about this error code could be found [here](https://developer.mozilla.org/en-US/docs/Web/HTTP/Status)" + "alertDescriptionFormat": "User generated multiple requests '{{RequestCount}}' that has resulted in error code '404', suggesting the possibility of file enumeration activity. It's important to investigate the source and patterns of these extensive 404 errors to identify potential security threats. Details about this error code could be found [here](https://developer.mozilla.org/en-US/docs/Web/HTTP/Status)", + "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP '{{SrcIpAddr}}' has been observed with performing file enumeration activity" } } }, @@ -1710,7 +1718,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PrivateIPInURL_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "PrivateIPInURL_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject11').analyticRuleVersion11]", @@ -1736,7 +1744,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "Exfiltration", "CommandAndControl" @@ -1751,58 +1759,58 @@ ], "entityMappings": [ { + "entityType": "IP", "fieldMappings": [ { - "columnName": "ip_inURL", - "identifier": "Address" + "identifier": "Address", + "columnName": "ip_inURL" } - ], - "entityType": "IP" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { - "Urls": "Urls", - "EventCount": "EventCount", "EventEndTime": "EventEndTime", - "EventStartTime": "EventStartTime" + "Urls": "Urls", + "EventStartTime": "EventStartTime", + "EventCount": "EventCount" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "Detected a private ip address '{{ip_inURL}}' carved in URL", - "alertDescriptionFormat": "User '{{SrcUsername}}' has been detected requesting URL '{{Urls}}' that contains private IP address '{{ip_inURL}}'. Encoding private IP addresses in a URL can be a method used by attackers to exfiltrate data from a compromised system" + "alertDescriptionFormat": "User '{{SrcUsername}}' has been detected requesting URL '{{Urls}}' that contains private IP address '{{ip_inURL}}'. Encoding private IP addresses in a URL can be a method used by attackers to exfiltrate data from a compromised system", + "alertDisplayNameFormat": "Detected a private ip address '{{ip_inURL}}' carved in URL" } } }, @@ -1857,7 +1865,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "RarelyRequestedResources_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "RarelyRequestedResources_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject12').analyticRuleVersion12]", @@ -1883,7 +1891,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "CommandAndControl" ], @@ -1893,44 +1901,44 @@ ], "entityMappings": [ { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SourceIP", - "identifier": "Address" + "identifier": "Address", + "columnName": "SourceIP" } - ], - "entityType": "IP" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "DestinationIP", - "identifier": "Address" + "identifier": "Address", + "columnName": "DestinationIP" } - ], - "entityType": "IP" + ] }, { + "entityType": "URL", "fieldMappings": [ { - "columnName": "RequestURL", - "identifier": "Url" + "identifier": "Url", + "columnName": "RequestURL" } - ], - "entityType": "URL" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { + "EventEndTime": "EventEndTime", "EventStartTime": "EventStartTime", - "EventCount": "EventCount", - "EventEndTime": "EventEndTime" + "EventCount": "EventCount" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "User with IP '{{SourceIP}}' has been observed making request for a rare resource", - "alertDescriptionFormat": "User requested (TotalEvents='{{EventCount}}') for URL '{{RequestURL}}' which contains a known script extension. The domain associated with this URL has not been accessed by any other user. This activity could be a potential beaconing activity to maintain control over compromised systems, receive instructions, or exfiltrate data" + "alertDescriptionFormat": "User requested (TotalEvents='{{EventCount}}') for URL '{{RequestURL}}' which contains a known script extension. The domain associated with this URL has not been accessed by any other user. This activity could be a potential beaconing activity to maintain control over compromised systems, receive instructions, or exfiltrate data", + "alertDisplayNameFormat": "User with IP '{{SourceIP}}' has been observed making request for a rare resource" } } }, @@ -1985,7 +1993,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "RareUserAgentDetected_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "RareUserAgentDetected_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject13').analyticRuleVersion13]", @@ -2011,7 +2019,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "InitialAccess" ], @@ -2021,68 +2029,68 @@ ], "entityMappings": [ { + "entityType": "URL", "fieldMappings": [ { - "columnName": "Url", - "identifier": "Url" + "identifier": "Url", + "columnName": "Url" } - ], - "entityType": "URL" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "DstIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "DstIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { - "EventStartTime": "EventStartTime", - "EventCount": "EventCount", "EventEndTime": "EventEndTime", "DstPortNumber": "DstPortNumber", - "HttpUserAgent": "HttpUserAgent" + "HttpUserAgent": "HttpUserAgent", + "EventStartTime": "EventStartTime", + "EventCount": "EventCount" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP '{{SrcIpAddr}}' has been observed accessing URL '{{Url}}' using a rare user agent.", - "alertDescriptionFormat": "The user agent '{{HttpUserAgent}}' has not been observed in the past 14 days. Conduct research on the user agent string to determine if it is associated with a known legitimate bot or if it is potentially linked to malicious activity. The URL is associated with the IP address '{{DstIpAddr}}'." + "alertDescriptionFormat": "The user agent '{{HttpUserAgent}}' has not been observed in the past 14 days. Conduct research on the user agent string to determine if it is associated with a known legitimate bot or if it is potentially linked to malicious activity. The URL is associated with the IP address '{{DstIpAddr}}'.", + "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP '{{SrcIpAddr}}' has been observed accessing URL '{{Url}}' using a rare user agent." } } }, @@ -2137,7 +2145,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "RequestToPotentiallyHarmfulFileTypes_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "RequestToPotentiallyHarmfulFileTypes_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject14').analyticRuleVersion14]", @@ -2163,7 +2171,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "InitialAccess", "Persistence", @@ -2176,67 +2184,67 @@ ], "entityMappings": [ { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "URL", "fieldMappings": [ { - "columnName": "Url", - "identifier": "Url" + "identifier": "Url", + "columnName": "Url" } - ], - "entityType": "URL" + ] }, { + "entityType": "File", "fieldMappings": [ { - "columnName": "requestedFileName", - "identifier": "Name" + "identifier": "Name", + "columnName": "requestedFileName" } - ], - "entityType": "File" + ] }, { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { + "EventEndTime": "EventEndTime", "EventStartTime": "EventStartTime", "EventCount": "EventCount", - "EventEndTime": "EventEndTime", "DstIpAddr": "DstIpAddr" }, "alertDetailsOverride": { - "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP address '{{SrcIpAddr}}' accessed a potentially harmful URL", - "alertDescriptionFormat": "User accessed URL - '{{Url}}' that contains a file - '{{requestedFileName}}' with risky extension. Downloading this file could pose a potential risk" + "alertDescriptionFormat": "User accessed URL - '{{Url}}' that contains a file - '{{requestedFileName}}' with risky extension. Downloading this file could pose a potential risk", + "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP address '{{SrcIpAddr}}' accessed a potentially harmful URL" } } }, @@ -2291,7 +2299,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ThreatInfoFoundInWebRequests_AnalyticalRules Analytics Rule with template version 3.0.3", + "description": "ThreatInfoFoundInWebRequests_AnalyticalRules Analytics Rule with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject15').analyticRuleVersion15]", @@ -2317,7 +2325,7 @@ "triggerOperator": "GreaterThan", "triggerThreshold": 0, "status": "Available", - "requiredDataConnectors": "[variables('TemplateEmptyArray')]", + "requiredDataConnectors": "[variables('TemplateEmptyArray')]", "tactics": [ "InitialAccess" ], @@ -2327,65 +2335,65 @@ ], "entityMappings": [ { + "entityType": "Host", "fieldMappings": [ { - "columnName": "SrcHostname", - "identifier": "HostName" + "identifier": "HostName", + "columnName": "SrcHostname" } - ], - "entityType": "Host" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "SrcIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "SrcIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "IP", "fieldMappings": [ { - "columnName": "DstIpAddr", - "identifier": "Address" + "identifier": "Address", + "columnName": "DstIpAddr" } - ], - "entityType": "IP" + ] }, { + "entityType": "Account", "fieldMappings": [ { - "columnName": "Name", - "identifier": "Name" + "identifier": "Name", + "columnName": "Name" }, { - "columnName": "UPNSuffix", - "identifier": "UPNSuffix" + "identifier": "UPNSuffix", + "columnName": "UPNSuffix" } - ], - "entityType": "Account" + ] }, { + "entityType": "URL", "fieldMappings": [ { - "columnName": "Url", - "identifier": "Url" + "identifier": "Url", + "columnName": "Url" } - ], - "entityType": "URL" + ] } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { - "EventStartTime": "EventStartTime", "EventCount": "EventCount", - "ThreatCategory": "ThreatCategory", "ThreatConfidence": "ThreatOriginalConfidence", - "ThreatName": "ThreatName", - "EvenEndTime": "EvenEndTime" + "EventStartTime": "EventStartTime", + "ThreatCategory": "ThreatCategory", + "EvenEndTime": "EvenEndTime", + "ThreatName": "ThreatName" }, "alertDetailsOverride": { "alertDisplayNameFormat": "User '{{SrcUsername}}' with IP address '{{SrcIpAddr}}' has been identified as being associated with a threat named '{{ThreatName}}'" @@ -2443,7 +2451,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "EmptyUserAgent_HuntingQueries Hunting Query with template version 3.0.3", + "description": "EmptyUserAgent_HuntingQueries Hunting Query with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject1').huntingQueryVersion1]", @@ -2452,7 +2460,7 @@ "resources": [ { "type": "Microsoft.OperationalInsights/savedSearches", - "apiVersion": "2022-10-01", + "apiVersion": "2025-07-01", "name": "Web_Session_Essentials_Hunting_Query_1", "location": "[parameters('workspace-location')]", "properties": { @@ -2528,7 +2536,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ExcessiveForbiddenRequestsDetected_HuntingQueries Hunting Query with template version 3.0.3", + "description": "ExcessiveForbiddenRequestsDetected_HuntingQueries Hunting Query with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject2').huntingQueryVersion2]", @@ -2537,7 +2545,7 @@ "resources": [ { "type": "Microsoft.OperationalInsights/savedSearches", - "apiVersion": "2022-10-01", + "apiVersion": "2025-07-01", "name": "Web_Session_Essentials_Hunting_Query_2", "location": "[parameters('workspace-location')]", "properties": { @@ -2613,7 +2621,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "IPAddressInURL_HuntingQueries Hunting Query with template version 3.0.3", + "description": "IPAddressInURL_HuntingQueries Hunting Query with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject3').huntingQueryVersion3]", @@ -2622,7 +2630,7 @@ "resources": [ { "type": "Microsoft.OperationalInsights/savedSearches", - "apiVersion": "2022-10-01", + "apiVersion": "2025-07-01", "name": "Web_Session_Essentials_Hunting_Query_3", "location": "[parameters('workspace-location')]", "properties": { @@ -2698,7 +2706,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "KaliLinuxUserAgentDetected_HuntingQueries Hunting Query with template version 3.0.3", + "description": "KaliLinuxUserAgentDetected_HuntingQueries Hunting Query with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject4').huntingQueryVersion4]", @@ -2707,7 +2715,7 @@ "resources": [ { "type": "Microsoft.OperationalInsights/savedSearches", - "apiVersion": "2022-10-01", + "apiVersion": "2025-07-01", "name": "Web_Session_Essentials_Hunting_Query_4", "location": "[parameters('workspace-location')]", "properties": { @@ -2783,7 +2791,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PotentialBeaconingDetected_LimitedDomainBased_HuntingQueries Hunting Query with template version 3.0.3", + "description": "PotentialBeaconingDetected_LimitedDomainBased_HuntingQueries Hunting Query with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject5').huntingQueryVersion5]", @@ -2792,7 +2800,7 @@ "resources": [ { "type": "Microsoft.OperationalInsights/savedSearches", - "apiVersion": "2022-10-01", + "apiVersion": "2025-07-01", "name": "Web_Session_Essentials_Hunting_Query_5", "location": "[parameters('workspace-location')]", "properties": { @@ -2868,7 +2876,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PotentialBeaconingDetected_SimilarSrcBytes_HuntingQueries Hunting Query with template version 3.0.3", + "description": "PotentialBeaconingDetected_SimilarSrcBytes_HuntingQueries Hunting Query with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject6').huntingQueryVersion6]", @@ -2877,7 +2885,7 @@ "resources": [ { "type": "Microsoft.OperationalInsights/savedSearches", - "apiVersion": "2022-10-01", + "apiVersion": "2025-07-01", "name": "Web_Session_Essentials_Hunting_Query_6", "location": "[parameters('workspace-location')]", "properties": { @@ -2953,7 +2961,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "PotentialBeaconingDetected_TimeDelta_HuntingQueries Hunting Query with template version 3.0.3", + "description": "PotentialBeaconingDetected_TimeDelta_HuntingQueries Hunting Query with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject7').huntingQueryVersion7]", @@ -2962,7 +2970,7 @@ "resources": [ { "type": "Microsoft.OperationalInsights/savedSearches", - "apiVersion": "2022-10-01", + "apiVersion": "2025-07-01", "name": "Web_Session_Essentials_Hunting_Query_7", "location": "[parameters('workspace-location')]", "properties": { @@ -3038,7 +3046,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "RequestFromBotsAndCrawlers_HuntingQueries Hunting Query with template version 3.0.3", + "description": "RequestFromBotsAndCrawlers_HuntingQueries Hunting Query with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject8').huntingQueryVersion8]", @@ -3047,7 +3055,7 @@ "resources": [ { "type": "Microsoft.OperationalInsights/savedSearches", - "apiVersion": "2022-10-01", + "apiVersion": "2025-07-01", "name": "Web_Session_Essentials_Hunting_Query_8", "location": "[parameters('workspace-location')]", "properties": { @@ -3123,7 +3131,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "ThreatInfoFoundInWebRequests_HuntingQueries Hunting Query with template version 3.0.3", + "description": "ThreatInfoFoundInWebRequests_HuntingQueries Hunting Query with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('huntingQueryObject9').huntingQueryVersion9]", @@ -3132,7 +3140,7 @@ "resources": [ { "type": "Microsoft.OperationalInsights/savedSearches", - "apiVersion": "2022-10-01", + "apiVersion": "2025-07-01", "name": "Web_Session_Essentials_Hunting_Query_9", "location": "[parameters('workspace-location')]", "properties": { @@ -3208,7 +3216,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "SummarizeWebSessionData Playbook with template version 3.0.3", + "description": "SummarizeWebSessionData Playbook with template version 3.0.4", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('playbookVersion1')]", @@ -3861,7 +3869,7 @@ "identity": { "type": "SystemAssigned" }, - "apiVersion": "2017-07-01", + "apiVersion": "2019-05-01", "dependsOn": [ "[[resourceId('Microsoft.Web/connections', variables('AzureloganalyticsdatacollectorConnectionName'))]", "[[resourceId('Microsoft.Web/connections', variables('AzuremonitorlogsConnectionName'))]" @@ -3921,15 +3929,15 @@ } ], "metadata": { - "title": "Summarize Web Session Data", - "description": "The 'SummarizeWebSessionData' Playbook helps with summarizing the Web Session logs and ingesting them into custom tables for persistence. Although enabling the summarization playbook for the Web Session solution is totally optional, we highly recommend enabling it for a better user experience in environments with high EPS (events per second) data ingestion. After installing the solution, it will be deployed under Playbook Templates in the Automation blade of Microsoft Sentinel. It can be configured and managed from the Manage Solution view in Content Hub. This playbook will create four custom data summarization tables: WebSession_Summarized_SrcInfo_CL, WebSession_Summarized_SrcIP_CL, WebSession_Summarized_DstIP_CL and WebSession_Summarized_ThreatInfo_CL.", + "title": "[Deprecated] Summarize Web Session Data", + "description": "The 'SummarizeWebSessionData' Playbook helps with summarizing the Web Session logs and ingesting them into custom tables for persistence. Although enabling the summarization playbook for the Web Session solution is totally optional, we highly recommend enabling it for a better user experience in environments with high EPS (events per second) data ingestion. After installing the solution, it will be deployed under Playbook Templates in the Automation blade of Microsoft Sentinel. It can be configured and managed from the Manage Solution view in Content Hub. This playbook will create four custom data summarization tables: WebSession_Summarized_SrcInfo_CL, WebSession_Summarized_SrcIP_CL, WebSession_Summarized_DstIP_CL and WebSession_Summarized_ThreatInfo_CL. \n **NOTE: It uses the legacy HTTP data collector API to ingest the data, which is about to be deprecated, so it is recommended to use the SummarizeWebSessionData_logingestion playbook instead.**", "postDeployment": [ "Authorize 'Azure Monitor Logs' and 'Azure Log Analytics Data Collector' API connections." ], + "lastUpdateTime": "2026-09-02T00:00:00Z", "tags": [ "Networking" ], - "lastUpdateTime": "2024-06-03T14:20:36.224Z", "releaseNotes": { "version": "1.0", "title": "[variables('blanks')]", @@ -3953,66 +3961,1424 @@ } }, { - "type": "Microsoft.OperationalInsights/workspaces/providers/contentPackages", + "type": "Microsoft.OperationalInsights/workspaces/providers/contentTemplates", "apiVersion": "2023-04-01-preview", + "name": "[variables('playbookTemplateSpecName2')]", "location": "[parameters('workspace-location')]", + "dependsOn": [ + "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" + ], "properties": { - "version": "3.0.3", - "kind": "Solution", - "contentSchemaVersion": "3.0.0", - "displayName": "Web Session Essentials", - "publisherDisplayName": "Microsoft Sentinel, Microsoft Corporation", - "descriptionHtml": "

Note: Please refer to the following before installing the solution:

\n

• Review the solution Release Notes

\n

• There may be known issues pertaining to this Solution, please refer to them before installing.

\n

Web Session Essentials is a domain solution and does not include any data connectors. The content in this solution requires one of the product solutions below, as well as any other connector or data source normalized to the ASIM.

\n

Prerequisite :-

\n

Install one or more of the listed solutions, or develop your custom ASIM parsers to unlock the value provided by this solution.

\n
    \n
  1. Palo Alto PAN-OS
  2. \n
  3. SquidProxy
  4. \n
  5. Vectra AI Stream
  6. \n
  7. Zscaler Internet Access
  8. \n
  9. IIS logs (via LA agent)
  10. \n
\n

Underlying Microsoft Technologies used:

\n

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

\n
    \n
  1. Product solutions as described above
  2. \n
  3. Logic app for data summarization
  4. \n
\n

Recommendation :-

\n

It is highly recommended to use the SummarizeWebSessionData logic app playbook provided with this solution as it will significantly improve the performance of the Workbook, Analytic rules & Hunting queries.

\n

Workbooks: 1, Analytic Rules: 15, Hunting Queries: 9, Playbooks: 1

\n

Learn more about Microsoft Sentinel | Learn more about Solutions

\n", - "contentKind": "Solution", - "contentProductId": "[variables('_solutioncontentProductId')]", - "id": "[variables('_solutioncontentProductId')]", - "icon": "", - "contentId": "[variables('_solutionId')]", - "parentId": "[variables('_solutionId')]", - "source": { - "kind": "Solution", - "name": "Web Session Essentials", - "sourceId": "[variables('_solutionId')]" - }, - "author": { - "name": "Microsoft", - "email": "[variables('_email')]" - }, - "support": { - "name": "Microsoft Corporation", - "email": "support@microsoft.com", - "tier": "Microsoft", - "link": "https://support.microsoft.com" - }, - "dependencies": { - "criteria": [ - { - "kind": "Workbook", - "contentId": "[variables('_workbookContentId1')]", - "version": "[variables('workbookVersion1')]" + "description": "SummarizeWebSessionData-logingestion Playbook with template version 3.0.4", + "mainTemplate": { + "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", + "contentVersion": "[variables('playbookVersion2')]", + "parameters": { + "PlaybookName": { + "defaultValue": "SummarizeWebSessionData-logingestion", + "type": "string" }, - { - "kind": "AnalyticsRule", - "contentId": "[variables('analyticRuleObject1')._analyticRulecontentId1]", - "version": "[variables('analyticRuleObject1').analyticRuleVersion1]" + "logAnalyticsName": { + "type": "string", + "metadata": { + "description": "Enter value for logAnalyticsName" + } }, - { - "kind": "AnalyticsRule", - "contentId": "[variables('analyticRuleObject2')._analyticRulecontentId2]", - "version": "[variables('analyticRuleObject2').analyticRuleVersion2]" + "resourceGroupName": { + "type": "string", + "metadata": { + "description": "Enter value for resourceGroupName" + } }, + "subscriptionId": { + "type": "string", + "metadata": { + "description": "Enter value for subscriptionId" + } + } + }, + "variables": { + "AzuremonitorlogsConnectionName": "[[concat('Azuremonitorlogs-', parameters('PlaybookName'))]", + "suffix": "[[uniqueString(resourceId(parameters('subscriptionId'), parameters('resourceGroupName'), 'Microsoft.OperationalInsights/workspaces', parameters('logAnalyticsName')))]", + "DCEName": "[[concat('web-session-summarization-dce-', variables('suffix'))]", + "DCRName": "[[concat('web-session-summarization-dcr-', variables('suffix'))]", + "workspaceResourceId": "[[resourceId(parameters('subscriptionId'), parameters('resourceGroupName'), 'Microsoft.OperationalInsights/workspaces', parameters('logAnalyticsName'))]", + "destinationName": "[[concat('webSessionSummarizationDestination', variables('suffix'))]", + "monitoringMetricsPublisherRoleId": "3913510d-42f4-4e42-8a64-420c390055eb", + "roleAssignmentName": "[[guid(resourceId('Microsoft.Insights/dataCollectionRules', variables('DCRName')), resourceId('Microsoft.Logic/workflows', parameters('PlaybookName')), variables('monitoringMetricsPublisherRoleId'))]", + "connection-8": "[[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Web/locations/', variables('workspace-location-inline'), '/managedApis/Azuremonitorlogs')]", + "_connection-8": "[[variables('connection-8')]", + "workspace-location-inline": "[concat('[resourceGroup().locatio', 'n]')]", + "workspace-name": "[parameters('workspace')]" + }, + "resources": [ { - "kind": "AnalyticsRule", - "contentId": "[variables('analyticRuleObject3')._analyticRulecontentId3]", - "version": "[variables('analyticRuleObject3').analyticRuleVersion3]" + "type": "Microsoft.Insights/dataCollectionEndpoints", + "apiVersion": "2022-06-01", + "name": "[[variables('DCEName')]", + "location": "[[variables('workspace-location-inline')]", + "kind": "Linux", + "properties": { + "description": "Data collection endpoint for Web Session Essentials summarized logs", + "networkAcls": { + "publicNetworkAccess": "Enabled" + } + } }, { - "kind": "AnalyticsRule", - "contentId": "[variables('analyticRuleObject4')._analyticRulecontentId4]", - "version": "[variables('analyticRuleObject4').analyticRuleVersion4]" + "type": "Microsoft.OperationalInsights/workspaces/tables", + "apiVersion": "2022-10-01", + "name": "[[concat(parameters('logAnalyticsName'), '/WebSession_Summarized_DstIPV1_CL')]", + "properties": { + "plan": "Analytics", + "schema": { + "name": "WebSession_Summarized_DstIPV1_CL", + "columns": [ + { + "name": "SrcBytes_d", + "type": "real" + }, + { + "name": "DstBytes_d", + "type": "real" + }, + { + "name": "EventCount_d", + "type": "real" + }, + { + "name": "DstIpAddr_s", + "type": "string" + }, + { + "name": "SrcIPIsPrivate_b", + "type": "boolean" + }, + { + "name": "DstPortNumber_d", + "type": "real" + }, + { + "name": "DestDomain_s", + "type": "string" + }, + { + "name": "DstHostname_s", + "type": "string" + }, + { + "name": "EventResult_s", + "type": "string" + }, + { + "name": "EventResultDetails_s", + "type": "string" + }, + { + "name": "EventProduct_s", + "type": "string" + }, + { + "name": "EventType_s", + "type": "string" + }, + { + "name": "TimeGenerated", + "type": "datetime" + }, + { + "name": "EventTime_t", + "type": "datetime" + } + ] + } + } }, { - "kind": "AnalyticsRule", + "type": "Microsoft.OperationalInsights/workspaces/tables", + "apiVersion": "2022-10-01", + "name": "[[concat(parameters('logAnalyticsName'), '/WebSession_Summarized_SrcInfoV1_CL')]", + "properties": { + "plan": "Analytics", + "schema": { + "name": "WebSession_Summarized_SrcInfoV1_CL", + "columns": [ + { + "name": "SrcBytes_d", + "type": "real" + }, + { + "name": "DstBytes_d", + "type": "real" + }, + { + "name": "EventCount_d", + "type": "real" + }, + { + "name": "HttpUserAgent_s", + "type": "string" + }, + { + "name": "EventResultDetails_s", + "type": "string" + }, + { + "name": "EventResult_s", + "type": "string" + }, + { + "name": "UrlCategory_s", + "type": "string" + }, + { + "name": "NetworkApplicationProtocol_s", + "type": "string" + }, + { + "name": "HttpRequestMethod_s", + "type": "string" + }, + { + "name": "HttpContentType_s", + "type": "string" + }, + { + "name": "EventProduct_s", + "type": "string" + }, + { + "name": "EventVendor_s", + "type": "string" + }, + { + "name": "EventType_s", + "type": "string" + }, + { + "name": "TimeGenerated", + "type": "datetime" + }, + { + "name": "EventTime_t", + "type": "datetime" + } + ] + } + } + }, + { + "type": "Microsoft.OperationalInsights/workspaces/tables", + "apiVersion": "2022-10-01", + "name": "[[concat(parameters('logAnalyticsName'), '/WebSession_Summarized_SrcIPV1_CL')]", + "properties": { + "plan": "Analytics", + "schema": { + "name": "WebSession_Summarized_SrcIPV1_CL", + "columns": [ + { + "name": "SrcBytes_d", + "type": "real" + }, + { + "name": "DstBytes_d", + "type": "real" + }, + { + "name": "EventCount_d", + "type": "real" + }, + { + "name": "SrcUsername_s", + "type": "string" + }, + { + "name": "SrcIpAddr_s", + "type": "string" + }, + { + "name": "SrcHostname_s", + "type": "string" + }, + { + "name": "DstIPIsPrivate_b", + "type": "boolean" + }, + { + "name": "DestDomain_s", + "type": "string" + }, + { + "name": "EventResult_s", + "type": "string" + }, + { + "name": "EventResultDetails_s", + "type": "string" + }, + { + "name": "EventProduct_s", + "type": "string" + }, + { + "name": "EventType_s", + "type": "string" + }, + { + "name": "TimeGenerated", + "type": "datetime" + }, + { + "name": "EventTime_t", + "type": "datetime" + } + ] + } + } + }, + { + "type": "Microsoft.OperationalInsights/workspaces/tables", + "apiVersion": "2022-10-01", + "name": "[[concat(parameters('logAnalyticsName'), '/WebSession_Summarized_ThreatInfoV1_CL')]", + "properties": { + "plan": "Analytics", + "schema": { + "name": "WebSession_Summarized_ThreatInfoV1_CL", + "columns": [ + { + "name": "EventCount_d", + "type": "real" + }, + { + "name": "ThreatName_s", + "type": "string" + }, + { + "name": "ThreatCategory_s", + "type": "string" + }, + { + "name": "ThreatRiskLevel_d", + "type": "real" + }, + { + "name": "ThreatOriginalConfidence_d", + "type": "real" + }, + { + "name": "EventSeverity_s", + "type": "string" + }, + { + "name": "ThreatField_s", + "type": "string" + }, + { + "name": "SrcIpAddr_s", + "type": "string" + }, + { + "name": "SrcUsername_s", + "type": "string" + }, + { + "name": "DestDomain_s", + "type": "string" + }, + { + "name": "EventResult_s", + "type": "string" + }, + { + "name": "DstIpAddr_s", + "type": "string" + }, + { + "name": "TimeGenerated", + "type": "datetime" + }, + { + "name": "EventTime_t", + "type": "datetime" + } + ] + } + } + }, + { + "type": "Microsoft.Insights/dataCollectionRules", + "apiVersion": "2022-06-01", + "name": "[[variables('DCRName')]", + "location": "[[variables('workspace-location-inline')]", + "dependsOn": [ + "[[resourceId('Microsoft.Insights/dataCollectionEndpoints', variables('DCEName'))]", + "[[resourceId('Microsoft.OperationalInsights/workspaces/tables', parameters('logAnalyticsName'), 'WebSession_Summarized_DstIPV1_CL')]", + "[[resourceId('Microsoft.OperationalInsights/workspaces/tables', parameters('logAnalyticsName'), 'WebSession_Summarized_SrcInfoV1_CL')]", + "[[resourceId('Microsoft.OperationalInsights/workspaces/tables', parameters('logAnalyticsName'), 'WebSession_Summarized_SrcIPV1_CL')]", + "[[resourceId('Microsoft.OperationalInsights/workspaces/tables', parameters('logAnalyticsName'), 'WebSession_Summarized_ThreatInfoV1_CL')]" + ], + "properties": { + "dataCollectionEndpointId": "[[resourceId('Microsoft.Insights/dataCollectionEndpoints', variables('DCEName'))]", + "streamDeclarations": { + "Custom-WebSession_Summarized_DstIPV1": { + "columns": [ + { + "name": "SrcBytes", + "type": "real" + }, + { + "name": "DstBytes", + "type": "real" + }, + { + "name": "EventCount", + "type": "real" + }, + { + "name": "DstIpAddr", + "type": "string" + }, + { + "name": "SrcIPIsPrivate", + "type": "boolean" + }, + { + "name": "DstPortNumber", + "type": "real" + }, + { + "name": "DestDomain", + "type": "string" + }, + { + "name": "DstHostname", + "type": "string" + }, + { + "name": "EventResult", + "type": "string" + }, + { + "name": "EventResultDetails", + "type": "string" + }, + { + "name": "EventProduct", + "type": "string" + }, + { + "name": "EventType", + "type": "string" + }, + { + "name": "TimeGenerated", + "type": "datetime" + }, + { + "name": "EventTime", + "type": "datetime" + } + ] + }, + "Custom-WebSession_Summarized_SrcInfoV1": { + "columns": [ + { + "name": "SrcBytes", + "type": "real" + }, + { + "name": "DstBytes", + "type": "real" + }, + { + "name": "EventCount", + "type": "real" + }, + { + "name": "HttpUserAgent", + "type": "string" + }, + { + "name": "EventResultDetails", + "type": "string" + }, + { + "name": "EventResult", + "type": "string" + }, + { + "name": "UrlCategory", + "type": "string" + }, + { + "name": "NetworkApplicationProtocol", + "type": "string" + }, + { + "name": "HttpRequestMethod", + "type": "string" + }, + { + "name": "HttpContentType", + "type": "string" + }, + { + "name": "EventProduct", + "type": "string" + }, + { + "name": "EventVendor", + "type": "string" + }, + { + "name": "EventType", + "type": "string" + }, + { + "name": "TimeGenerated", + "type": "datetime" + }, + { + "name": "EventTime", + "type": "datetime" + } + ] + }, + "Custom-WebSession_Summarized_SrcIPV1": { + "columns": [ + { + "name": "SrcBytes", + "type": "real" + }, + { + "name": "DstBytes", + "type": "real" + }, + { + "name": "EventCount", + "type": "real" + }, + { + "name": "SrcUsername", + "type": "string" + }, + { + "name": "SrcIpAddr", + "type": "string" + }, + { + "name": "SrcHostname", + "type": "string" + }, + { + "name": "DstIPIsPrivate", + "type": "boolean" + }, + { + "name": "DestDomain", + "type": "string" + }, + { + "name": "EventResult", + "type": "string" + }, + { + "name": "EventResultDetails", + "type": "string" + }, + { + "name": "EventProduct", + "type": "string" + }, + { + "name": "EventType", + "type": "string" + }, + { + "name": "TimeGenerated", + "type": "datetime" + }, + { + "name": "EventTime", + "type": "datetime" + } + ] + }, + "Custom-WebSession_Summarized_ThreatInfoV1": { + "columns": [ + { + "name": "EventCount", + "type": "real" + }, + { + "name": "ThreatName", + "type": "string" + }, + { + "name": "ThreatCategory", + "type": "string" + }, + { + "name": "ThreatRiskLevel", + "type": "real" + }, + { + "name": "ThreatOriginalConfidence", + "type": "real" + }, + { + "name": "EventSeverity", + "type": "string" + }, + { + "name": "ThreatField", + "type": "string" + }, + { + "name": "SrcIpAddr", + "type": "string" + }, + { + "name": "SrcUsername", + "type": "string" + }, + { + "name": "DestDomain", + "type": "string" + }, + { + "name": "EventResult", + "type": "string" + }, + { + "name": "DstIpAddr", + "type": "string" + }, + { + "name": "TimeGenerated", + "type": "datetime" + }, + { + "name": "EventTime", + "type": "datetime" + } + ] + } + }, + "destinations": { + "logAnalytics": [ + { + "workspaceResourceId": "[[variables('workspaceResourceId')]", + "name": "[[variables('destinationName')]" + } + ] + }, + "dataFlows": [ + { + "streams": [ + "Custom-WebSession_Summarized_DstIPV1" + ], + "destinations": [ + "[[variables('destinationName')]" + ], + "transformKql": "source | project SrcBytes_d=toreal(SrcBytes), DstBytes_d=toreal(DstBytes), EventCount_d=toreal(EventCount), DstIpAddr_s=tostring(DstIpAddr), SrcIPIsPrivate_b=tobool(SrcIPIsPrivate), DstPortNumber_d=toreal(DstPortNumber), DestDomain_s=tostring(DestDomain), DstHostname_s=tostring(DstHostname), EventResult_s=tostring(EventResult), EventResultDetails_s=tostring(EventResultDetails), EventProduct_s=tostring(EventProduct), EventType_s=tostring(EventType), TimeGenerated=todatetime(TimeGenerated), EventTime_t=todatetime(EventTime)", + "outputStream": "Custom-WebSession_Summarized_DstIPV1_CL" + }, + { + "streams": [ + "Custom-WebSession_Summarized_SrcInfoV1" + ], + "destinations": [ + "[[variables('destinationName')]" + ], + "transformKql": "source | project SrcBytes_d=toreal(SrcBytes), DstBytes_d=toreal(DstBytes), EventCount_d=toreal(EventCount), HttpUserAgent_s=tostring(HttpUserAgent), EventResultDetails_s=tostring(EventResultDetails), EventResult_s=tostring(EventResult), UrlCategory_s=tostring(UrlCategory), NetworkApplicationProtocol_s=tostring(NetworkApplicationProtocol), HttpRequestMethod_s=tostring(HttpRequestMethod), HttpContentType_s=tostring(HttpContentType), EventProduct_s=tostring(EventProduct), EventVendor_s=tostring(EventVendor), EventType_s=tostring(EventType), TimeGenerated=todatetime(TimeGenerated), EventTime_t=todatetime(EventTime)", + "outputStream": "Custom-WebSession_Summarized_SrcInfoV1_CL" + }, + { + "streams": [ + "Custom-WebSession_Summarized_SrcIPV1" + ], + "destinations": [ + "[[variables('destinationName')]" + ], + "transformKql": "source | project SrcBytes_d=toreal(SrcBytes), DstBytes_d=toreal(DstBytes), EventCount_d=toreal(EventCount), SrcUsername_s=tostring(SrcUsername), SrcIpAddr_s=tostring(SrcIpAddr), SrcHostname_s=tostring(SrcHostname), DstIPIsPrivate_b=tobool(DstIPIsPrivate), DestDomain_s=tostring(DestDomain), EventResult_s=tostring(EventResult), EventResultDetails_s=tostring(EventResultDetails), EventProduct_s=tostring(EventProduct), EventType_s=tostring(EventType), TimeGenerated=todatetime(TimeGenerated), EventTime_t=todatetime(EventTime)", + "outputStream": "Custom-WebSession_Summarized_SrcIPV1_CL" + }, + { + "streams": [ + "Custom-WebSession_Summarized_ThreatInfoV1" + ], + "destinations": [ + "[[variables('destinationName')]" + ], + "transformKql": "source | project EventCount_d=toreal(EventCount), ThreatName_s=tostring(ThreatName), ThreatCategory_s=tostring(ThreatCategory), ThreatRiskLevel_d=toreal(ThreatRiskLevel), ThreatOriginalConfidence_d=toreal(ThreatOriginalConfidence), EventSeverity_s=tostring(EventSeverity), ThreatField_s=tostring(ThreatField), SrcIpAddr_s=tostring(SrcIpAddr), SrcUsername_s=tostring(SrcUsername), DestDomain_s=tostring(DestDomain), EventResult_s=tostring(EventResult), DstIpAddr_s=tostring(DstIpAddr), TimeGenerated=todatetime(TimeGenerated), EventTime_t=todatetime(EventTime)", + "outputStream": "Custom-WebSession_Summarized_ThreatInfoV1_CL" + } + ] + } + }, + { + "properties": { + "provisioningState": "Succeeded", + "state": "Disabled", + "definition": { + "$schema": "https://schema.management.azure.com/providers/Microsoft.Logic/schemas/2016-06-01/workflowdefinition.json#", + "contentVersion": "1.0.0.0", + "parameters": { + "$connections": { + "type": "Object" + }, + "logAnalyticsName": { + "defaultValue": "[[parameters('logAnalyticsName')]", + "type": "string" + }, + "resourceGroupName": { + "defaultValue": "[[parameters('resourceGroupName')]", + "type": "string" + }, + "subscriptionId": { + "defaultValue": "[[parameters('subscriptionId')]", + "type": "string" + }, + "ingestionEndpoint": { + "defaultValue": "[[concat(reference(resourceId('Microsoft.Insights/dataCollectionEndpoints', variables('DCEName'))).logsIngestion.endpoint, '/dataCollectionRules/', reference(resourceId('Microsoft.Insights/dataCollectionRules', variables('DCRName'))).immutableId, '/streams/')]", + "type": "string" + } + }, + "triggers": { + "Recurrence": { + "recurrence": { + "frequency": "Hour", + "interval": 1 + }, + "evaluatedRecurrence": { + "frequency": "Hour", + "interval": 1 + }, + "type": "Recurrence" + } + }, + "actions": { + "Condition_DstIP": { + "actions": { + "For_each_DstIP": { + "foreach": "@variables('multipleArraysDstIP')", + "actions": { + "Send_Data_DstIP": { + "type": "Http", + "inputs": { + "body": "@items('For_each_DstIP')", + "headers": { + "Content-Type": "application/json" + }, + "authentication": { + "type": "ManagedServiceIdentity", + "audience": "https://monitor.azure.com/" + }, + "method": "POST", + "uri": "@concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_DstIPV1', '?api-version=2023-01-01')" + } + } + }, + "runAfter": { + "Set_variable_-_multipleArraysDstIP": [ + "Succeeded" + ] + }, + "type": "Foreach" + }, + "Set_variable_-_multipleArraysDstIP": { + "type": "SetVariable", + "inputs": { + "name": "multipleArraysDstIP", + "value": "@chunk(body('Run_query_and_list_results_DstIP')?['value'],div(variables('MaxByteSizeAllowed'),div(variables('TotalCharacterLengthDstIP'),variables('ArraySizeDstIP'))))" + } + } + }, + "runAfter": { + "Initialize_variable_-_multipleArraysDstIP": [ + "Succeeded" + ] + }, + "expression": { + "and": [ + { + "greater": [ + "@variables('ArraySizeDstIP')", + 0 + ] + } + ] + }, + "type": "If" + }, + "Condition_SourceInfo": { + "actions": { + "For_each_-_SubArray_-_SourceInfo": { + "foreach": "@variables('multipleArraysSourceInfo')", + "actions": { + "Send_Data_SourceInfo": { + "type": "Http", + "inputs": { + "body": "@items('For_each_-_SubArray_-_SourceInfo')", + "headers": { + "Content-Type": "application/json" + }, + "authentication": { + "type": "ManagedServiceIdentity", + "audience": "https://monitor.azure.com/" + }, + "method": "POST", + "uri": "@concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_SrcInfoV1', '?api-version=2023-01-01')" + } + } + }, + "runAfter": { + "Set_variable": [ + "Succeeded" + ] + }, + "type": "Foreach" + }, + "Set_variable": { + "type": "SetVariable", + "inputs": { + "name": "multipleArraysSourceInfo", + "value": "@chunk(body('Run_query_and_list_results_SourceInfo')?['value'],div(variables('MaxByteSizeAllowed'),div(variables('TotalCharacterLengthSourceInfo'),variables('ArraySizeSourceInfo'))))" + } + } + }, + "runAfter": { + "Initialize_variable_-_multipleArrays_-_SourceInfo": [ + "Succeeded" + ] + }, + "expression": { + "and": [ + { + "greater": [ + "@variables('ArraySizeSourceInfo')", + 0 + ] + } + ] + }, + "type": "If" + }, + "Condition_SrcIP": { + "actions": { + "For_each": { + "foreach": "@variables('multipleArraysSrcIP')", + "actions": { + "Send_Data_SrcIP": { + "type": "Http", + "inputs": { + "body": "@items('For_each')", + "headers": { + "Content-Type": "application/json" + }, + "authentication": { + "type": "ManagedServiceIdentity", + "audience": "https://monitor.azure.com/" + }, + "method": "POST", + "uri": "@concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_SrcIPV1', '?api-version=2023-01-01')" + } + } + }, + "runAfter": { + "Set_variable_multipleArraysIP": [ + "Succeeded" + ] + }, + "type": "Foreach" + }, + "Set_variable_multipleArraysIP": { + "type": "SetVariable", + "inputs": { + "name": "multipleArraysSrcIP", + "value": "@chunk(body('Run_query_and_list_results_SrcIP')?['value'],div(variables('MaxByteSizeAllowed'),div(variables('TotalCharacterLengthSrcIP'),variables('ArraySizeSrcIP'))))" + } + } + }, + "runAfter": { + "Initialize_variable_-_multipleArraysSrcIP": [ + "Succeeded" + ] + }, + "expression": { + "and": [ + { + "greater": [ + "@variables('ArraySizeSrcIP')", + 0 + ] + } + ] + }, + "type": "If" + }, + "Condition_ThreatInfo": { + "actions": { + "For_each_ThreatInfo": { + "foreach": "@variables('multipleArraysThreatInfo')", + "actions": { + "Send_Data": { + "type": "Http", + "inputs": { + "body": "@items('For_each_ThreatInfo')", + "headers": { + "Content-Type": "application/json" + }, + "authentication": { + "type": "ManagedServiceIdentity", + "audience": "https://monitor.azure.com/" + }, + "method": "POST", + "uri": "@concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_ThreatInfoV1', '?api-version=2023-01-01')" + } + } + }, + "runAfter": { + "Set_variable_-_multipleArraysThreatInfo": [ + "Succeeded" + ] + }, + "type": "Foreach" + }, + "Set_variable_-_multipleArraysThreatInfo": { + "type": "SetVariable", + "inputs": { + "name": "multipleArraysThreatInfo", + "value": "@chunk(body('Run_query_and_list_results_ThreatInfo')?['value'],div(variables('MaxByteSizeAllowed'),div(variables('TotalCharacterLengthThreatInfo'),variables('ArraySizeThreatInfo'))))" + } + } + }, + "runAfter": { + "Initialize_variable_-_multipleArraysThreatInfo": [ + "Succeeded" + ] + }, + "expression": { + "and": [ + { + "greater": [ + "@variables('ArraySizeThreatInfo')", + 0 + ] + } + ] + }, + "type": "If" + }, + "Initialize_variable_-_ArraySizeDstIP": { + "runAfter": { + "Run_query_and_list_results_DstIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "ArraySizeDstIP", + "type": "integer", + "value": "@length(body('Run_query_and_list_results_DstIP')?['value'])" + } + ] + } + }, + "Initialize_variable_-_ArraySizeSrcIP": { + "runAfter": { + "Run_query_and_list_results_SrcIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "ArraySizeSrcIP", + "type": "integer", + "value": "@length(body('Run_query_and_list_results_SrcIP')?['value'])" + } + ] + } + }, + "Initialize_variable_-_ArraySizeThreatInfo": { + "runAfter": { + "Run_query_and_list_results_ThreatInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "ArraySizeThreatInfo", + "type": "integer", + "value": "@length(body('Run_query_and_list_results_ThreatInfo')?['value'])" + } + ] + } + }, + "Initialize_variable_-_ArraySize_-_SourceInfo": { + "runAfter": { + "Run_query_and_list_results_SourceInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "ArraySizeSourceInfo", + "type": "integer", + "value": "@length(body('Run_query_and_list_results_SourceInfo')?['value'])" + } + ] + } + }, + "Initialize_variable_-_TotalCharacterLengthSrcIP": { + "runAfter": { + "Initialize_variable_-_ArraySizeSrcIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "TotalCharacterLengthSrcIP", + "type": "integer", + "value": "@length(string(body('Run_query_and_list_results_SrcIP')?['value']))" + } + ] + } + }, + "Initialize_variable_-_TotalCharacterLengthThreatInfo": { + "runAfter": { + "Initialize_variable_-_ArraySizeThreatInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "TotalCharacterLengthThreatInfo", + "type": "integer", + "value": "@length(string(body('Run_query_and_list_results_ThreatInfo')?['value']))" + } + ] + } + }, + "Initialize_variable_-_TotalCharacterLength_-_SourceInfo": { + "runAfter": { + "Initialize_variable_-_ArraySize_-_SourceInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "TotalCharacterLengthSourceInfo", + "type": "integer", + "value": "@length(string(body('Run_query_and_list_results_SourceInfo')?['value']))" + } + ] + } + }, + "Initialize_variable_-_TotalCharaterLengthDstIP": { + "runAfter": { + "Initialize_variable_-_ArraySizeDstIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "TotalCharacterLengthDstIP", + "type": "integer", + "value": "@length(string(body('Run_query_and_list_results_DstIP')?['value']))" + } + ] + } + }, + "Initialize_variable_-_multipleArraysDstIP": { + "runAfter": { + "Initialize_variable_-_TotalCharaterLengthDstIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "multipleArraysDstIP", + "type": "array" + } + ] + } + }, + "Initialize_variable_-_multipleArraysSrcIP": { + "runAfter": { + "Initialize_variable_-_TotalCharacterLengthSrcIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "multipleArraysSrcIP", + "type": "array" + } + ] + } + }, + "Initialize_variable_-_multipleArraysThreatInfo": { + "runAfter": { + "Initialize_variable_-_TotalCharacterLengthThreatInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "multipleArraysThreatInfo", + "type": "array" + } + ] + } + }, + "Initialize_variable_-_multipleArrays_-_SourceInfo": { + "runAfter": { + "Initialize_variable_-_TotalCharacterLength_-_SourceInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "multipleArraysSourceInfo", + "type": "array" + } + ] + } + }, + "MaxRequestSizeAllowed": { + "runAfter": { + "nowTime": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "MaxByteSizeAllowed", + "type": "integer", + "value": 26214400 + } + ] + } + }, + "Run_query_and_list_results_DstIP": { + "runAfter": { + "MaxRequestSizeAllowed": [ + "Succeeded" + ] + }, + "type": "ApiConnection", + "inputs": { + "body": "let nowTime = todatetime(\"@{variables('nowTime')}\");\nlet lastRecievedTime = toscalar (\n union isfuzzy=true\n (\n WebSession_Summarized_DstIPV1_CL \n | summarize max(EventTime_t)\n | extend max_TimeGenerated = datetime_add('hour',1,bin(max_EventTime_t,1h))\n ),\n (\n print (nowTime)\n | extend max_TimeGenerated = datetime_add('day',-1,bin(print_0,1h)) \n | project-away print_0\n )\n | summarize max(max_TimeGenerated)\n );\n_Im_WebSession(starttime=lastRecievedTime,endtime=bin(nowTime,1h))\n| where TimeGenerated < bin(nowTime,1h)\n| summarize SrcBytes = sum(SrcBytes), DstBytes = sum(DstBytes), EventCount = count() by DstIpAddr, SrcIPIsPrivate = ipv4_is_private(SrcIpAddr), DstPortNumber, DestDomain = tostring(parse_url(Url)[\"Host\"]), DstHostname, EventResult, EventResultDetails, EventProduct, EventType, bin(TimeGenerated,1h)\n| extend EventTime = TimeGenerated", + "host": { + "connection": { + "name": "@parameters('$connections')['azuremonitorlogs']['connectionId']" + } + }, + "method": "post", + "path": "/queryData", + "queries": { + "resourcegroups": "@parameters('resourceGroupName')", + "resourcename": "@parameters('logAnalyticsName')", + "resourcetype": "Log Analytics Workspace", + "subscriptions": "@parameters('subscriptionId')", + "timerange": "Last 1 day" + } + } + }, + "Run_query_and_list_results_SourceInfo": { + "runAfter": { + "MaxRequestSizeAllowed": [ + "Succeeded" + ] + }, + "type": "ApiConnection", + "inputs": { + "body": "let nowTime = todatetime(\"@{variables('nowTime')}\");\nlet lastRecievedTime = toscalar (\n union isfuzzy=true\n (\n WebSession_Summarized_SrcInfoV1_CL \n | summarize max(EventTime_t)\n | extend max_TimeGenerated = datetime_add('hour',1,bin(max_EventTime_t,1h))\n ),\n (\n print (nowTime)\n | extend max_TimeGenerated = datetime_add('day',-1,bin(print_0,1h)) \n | project-away print_0\n )\n | summarize max(max_TimeGenerated)\n );\n_Im_WebSession(starttime=lastRecievedTime,endtime=bin(nowTime,1h))\n| where TimeGenerated < bin(nowTime,1h)\n| summarize SrcBytes = sum(SrcBytes), DstBytes = sum(DstBytes), EventCount = count() by HttpUserAgent, EventResultDetails, EventResult, UrlCategory, NetworkApplicationProtocol, HttpRequestMethod, HttpContentType, EventTime = bin(TimeGenerated, 1h), EventProduct, EventVendor, EventType, bin(TimeGenerated,1h)\n| extend EventTime = TimeGenerated", + "host": { + "connection": { + "name": "@parameters('$connections')['azuremonitorlogs']['connectionId']" + } + }, + "method": "post", + "path": "/queryData", + "queries": { + "resourcegroups": "@parameters('resourceGroupName')", + "resourcename": "@parameters('logAnalyticsName')", + "resourcetype": "Log Analytics Workspace", + "subscriptions": "@parameters('subscriptionId')", + "timerange": "Last 1 day" + } + } + }, + "Run_query_and_list_results_SrcIP": { + "runAfter": { + "MaxRequestSizeAllowed": [ + "Succeeded" + ] + }, + "type": "ApiConnection", + "inputs": { + "body": "let nowTime = todatetime(\"@{variables('nowTime')}\");\nlet lastRecievedTime = toscalar (\n union isfuzzy=true\n (\n WebSession_Summarized_SrcIPV1_CL \n | summarize max(EventTime_t)\n | extend max_TimeGenerated = datetime_add('hour',1,bin(max_EventTime_t,1h))\n ),\n (\n print (nowTime)\n | extend max_TimeGenerated = datetime_add('day',-1,bin(print_0,1h)) \n | project-away print_0\n )\n | summarize max(max_TimeGenerated)\n );\n_Im_WebSession(starttime=lastRecievedTime,endtime=bin(nowTime,1h))\n| where TimeGenerated < bin(nowTime,1h)\n| summarize SrcBytes = sum(SrcBytes), DstBytes = sum(DstBytes), EventCount = count() by SrcUsername, SrcIpAddr, SrcHostname, DstIPIsPrivate = ipv4_is_private(DstIpAddr), DestDomain = tostring(parse_url(Url)[\"Host\"]), EventResult, EventResultDetails, EventProduct, EventType, bin(TimeGenerated,1h)\n| extend EventTime = TimeGenerated", + "host": { + "connection": { + "name": "@parameters('$connections')['azuremonitorlogs']['connectionId']" + } + }, + "method": "post", + "path": "/queryData", + "queries": { + "resourcegroups": "@parameters('resourceGroupName')", + "resourcename": "@parameters('logAnalyticsName')", + "resourcetype": "Log Analytics Workspace", + "subscriptions": "@parameters('subscriptionId')", + "timerange": "Last 1 day" + } + } + }, + "Run_query_and_list_results_ThreatInfo": { + "runAfter": { + "MaxRequestSizeAllowed": [ + "Succeeded" + ] + }, + "type": "ApiConnection", + "inputs": { + "body": "let nowTime = todatetime(\"@{variables('nowTime')}\");\nlet lastRecievedTime = toscalar (\n union isfuzzy=true\n (\n WebSession_Summarized_ThreatInfoV1_CL \n | summarize max(EventTime_t)\n | extend max_TimeGenerated = datetime_add('hour',1,bin(max_EventTime_t,1h))\n ),\n (\n print (nowTime)\n | extend max_TimeGenerated = datetime_add('day',-1,bin(print_0,1h)) \n | project-away print_0\n )\n | summarize max(max_TimeGenerated)\n );\n_Im_WebSession(starttime=lastRecievedTime,endtime=bin(nowTime,1h))\n| where TimeGenerated < bin(nowTime,1h)\n| where (ThreatName != 'None' and isnotempty(ThreatName)) or (ThreatCategory != 'None' and isnotempty(ThreatCategory)) or ThreatRiskLevel > 60 or toint(ThreatOriginalConfidence) > 0 or EventSeverity in ('Medium','High') or isnotempty(ThreatField)\n| summarize EventCount=count() by ThreatName, ThreatCategory, ThreatRiskLevel, toint(ThreatOriginalConfidence), EventSeverity, ThreatField, SrcIpAddr, SrcUsername, DestDomain = tostring(parse_url(Url)[\"Host\"]), bin(TimeGenerated, 1h), EventResult, DstIpAddr\n| extend EventTime = TimeGenerated", + "host": { + "connection": { + "name": "@parameters('$connections')['azuremonitorlogs']['connectionId']" + } + }, + "method": "post", + "path": "/queryData", + "queries": { + "resourcegroups": "@parameters('resourceGroupName')", + "resourcename": "@parameters('logAnalyticsName')", + "resourcetype": "Log Analytics Workspace", + "subscriptions": "@parameters('subscriptionId')", + "timerange": "Last 1 day" + } + } + }, + "nowTime": { + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "nowTime", + "type": "string", + "value": "@{utcNow()}" + } + ] + } + } + } + }, + "parameters": { + "$connections": { + "value": { + "azuremonitorlogs": { + "connectionId": "[[resourceId('Microsoft.Web/connections', variables('AzuremonitorlogsConnectionName'))]", + "connectionName": "[[variables('AzuremonitorlogsConnectionName')]", + "id": "[[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Web/locations/', variables('workspace-location-inline'), '/managedApis/Azuremonitorlogs')]" + } + } + } + } + }, + "name": "[[parameters('PlaybookName')]", + "type": "Microsoft.Logic/workflows", + "location": "[[variables('workspace-location-inline')]", + "tags": { + "hidden-SentinelTemplateName": "SummarizeWebSessionData", + "hidden-SentinelTemplateVersion": "1.0", + "hidden-SentinelWorkspaceId": "[[variables('workspaceResourceId')]" + }, + "identity": { + "type": "SystemAssigned" + }, + "apiVersion": "2019-05-01", + "dependsOn": [ + "[[resourceId('Microsoft.Insights/dataCollectionRules', variables('DCRName'))]", + "[[resourceId('Microsoft.Web/connections', variables('AzuremonitorlogsConnectionName'))]" + ] + }, + { + "type": "Microsoft.Web/connections", + "apiVersion": "2016-06-01", + "name": "[[variables('AzuremonitorlogsConnectionName')]", + "location": "[[variables('workspace-location-inline')]", + "kind": "V1", + "properties": { + "displayName": "[[variables('AzuremonitorlogsConnectionName')]", + "api": { + "id": "[[variables('_connection-8')]" + } + } + }, + { + "type": "Microsoft.Authorization/roleAssignments", + "apiVersion": "2022-04-01", + "name": "[[variables('roleAssignmentName')]", + "scope": "[[resourceId('Microsoft.Insights/dataCollectionRules', variables('DCRName'))]", + "dependsOn": [ + "[[resourceId('Microsoft.Insights/dataCollectionRules', variables('DCRName'))]", + "[[resourceId('Microsoft.Logic/workflows', parameters('PlaybookName'))]" + ], + "properties": { + "roleDefinitionId": "[[subscriptionResourceId('Microsoft.Authorization/roleDefinitions', variables('monitoringMetricsPublisherRoleId'))]", + "principalId": "[[reference(resourceId('Microsoft.Logic/workflows', parameters('PlaybookName')), '2019-05-01', 'Full').identity.principalId]", + "principalType": "ServicePrincipal" + } + }, + { + "type": "Microsoft.OperationalInsights/workspaces/providers/metadata", + "apiVersion": "2022-01-01-preview", + "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat('Playbook-', last(split(variables('playbookId2'),'/'))))]", + "properties": { + "parentId": "[variables('playbookId2')]", + "contentId": "[variables('_playbookContentId2')]", + "kind": "Playbook", + "version": "[variables('playbookVersion2')]", + "source": { + "kind": "Solution", + "name": "Web Session Essentials", + "sourceId": "[variables('_solutionId')]" + }, + "author": { + "name": "Microsoft", + "email": "[variables('_email')]" + }, + "support": { + "name": "Microsoft Corporation", + "email": "support@microsoft.com", + "tier": "Microsoft", + "link": "https://support.microsoft.com" + } + } + } + ], + "metadata": { + "title": "Summarize Web Session Data using Log Ingestion API", + "description": "The 'SummarizeWebSessionData' Playbook helps with summarizing the Web Session logs and ingesting them into custom tables for persistence. Although enabling the summarization playbook for the Web Session solution is totally optional, we highly recommend enabling it for a better user experience in environments with high EPS (events per second) data ingestion. After installing the solution, it will be deployed under Playbook Templates in the Automation blade of Microsoft Sentinel. It can be configured and managed from the Manage Solution view in Content Hub. This playbook will create four custom data summarization tables: WebSession_Summarized_SrcInfoV1_CL, WebSession_Summarized_SrcIPV1_CL, WebSession_Summarized_DstIPV1_CL and WebSession_Summarized_ThreatInfoV1_CL.", + "postDeployment": [ + "Authorize the 'Azure Monitor Logs' API connection. Log ingestion uses the playbook's managed identity." + ], + "lastUpdateTime": "2026-09-02T00:00:00Z", + "tags": [ + "Networking" + ], + "releaseNotes": { + "version": "1.0", + "title": "[variables('blanks')]", + "notes": [ + "Initial version" + ] + } + } + }, + "packageKind": "Solution", + "packageVersion": "[variables('_solutionVersion')]", + "packageName": "[variables('_solutionName')]", + "packageId": "[variables('_solutionId')]", + "contentSchemaVersion": "3.0.0", + "contentId": "[variables('_playbookContentId2')]", + "contentKind": "Playbook", + "displayName": "SummarizeWebSessionData-logingestion", + "contentProductId": "[variables('_playbookcontentProductId2')]", + "id": "[variables('_playbookcontentProductId2')]", + "version": "[variables('playbookVersion2')]" + } + }, + { + "type": "Microsoft.OperationalInsights/workspaces/providers/contentPackages", + "apiVersion": "2023-04-01-preview", + "location": "[parameters('workspace-location')]", + "properties": { + "version": "3.0.4", + "kind": "Solution", + "contentSchemaVersion": "3.0.0", + "displayName": "Web Session Essentials", + "publisherDisplayName": "Microsoft Sentinel, Microsoft Corporation", + "descriptionHtml": "

Note: Please refer to the following before installing the solution:

\n

• Review the solution Release Notes

\n

• There may be known issues pertaining to this Solution, please refer to them before installing.

\n

Web Session Essentials is a domain solution and does not include any data connectors. The content in this solution requires one of the product solutions below, as well as any other connector or data source normalized to the ASIM.

\n

Prerequisite :-

\n

Install one or more of the listed solutions, or develop your custom ASIM parsers to unlock the value provided by this solution.

\n
    \n
  1. Palo Alto PAN-OS
  2. \n
  3. SquidProxy
  4. \n
  5. Vectra AI Stream
  6. \n
  7. Zscaler Internet Access
  8. \n
  9. IIS logs (via LA agent)
  10. \n
\n

Underlying Microsoft Technologies used:

\n

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

\n
    \n
  1. Product solutions as described above
  2. \n
  3. Logic app for data summarization
  4. \n
\n

Recommendation :-

\n

It is highly recommended to use the SummarizeWebSessionData logic app playbook provided with this solution as it will significantly improve the performance of the Workbook, Analytic rules & Hunting queries.\nNOTE: This solution includes the playbook SummarizeWebSessionData, which uses the legacy HTTP data collector API to ingest data. Since that API is about to be deprecated, we recommend using the SummarizeWebSessionData_logingestion playbook instead.

\n

Workbooks: 1, Analytic Rules: 15, Hunting Queries: 9, Playbooks: 2

\n

Learn more about Microsoft Sentinel | Learn more about Solutions

\n", + "contentKind": "Solution", + "contentProductId": "[variables('_solutioncontentProductId')]", + "id": "[variables('_solutioncontentProductId')]", + "icon": "", + "contentId": "[variables('_solutionId')]", + "parentId": "[variables('_solutionId')]", + "source": { + "kind": "Solution", + "name": "Web Session Essentials", + "sourceId": "[variables('_solutionId')]" + }, + "author": { + "name": "Microsoft", + "email": "[variables('_email')]" + }, + "support": { + "name": "Microsoft Corporation", + "email": "support@microsoft.com", + "tier": "Microsoft", + "link": "https://support.microsoft.com" + }, + "dependencies": { + "criteria": [ + { + "kind": "Workbook", + "contentId": "[variables('_workbookContentId1')]", + "version": "[variables('workbookVersion1')]" + }, + { + "kind": "AnalyticsRule", + "contentId": "[variables('analyticRuleObject1')._analyticRulecontentId1]", + "version": "[variables('analyticRuleObject1').analyticRuleVersion1]" + }, + { + "kind": "AnalyticsRule", + "contentId": "[variables('analyticRuleObject2')._analyticRulecontentId2]", + "version": "[variables('analyticRuleObject2').analyticRuleVersion2]" + }, + { + "kind": "AnalyticsRule", + "contentId": "[variables('analyticRuleObject3')._analyticRulecontentId3]", + "version": "[variables('analyticRuleObject3').analyticRuleVersion3]" + }, + { + "kind": "AnalyticsRule", + "contentId": "[variables('analyticRuleObject4')._analyticRulecontentId4]", + "version": "[variables('analyticRuleObject4').analyticRuleVersion4]" + }, + { + "kind": "AnalyticsRule", "contentId": "[variables('analyticRuleObject5')._analyticRulecontentId5]", "version": "[variables('analyticRuleObject5').analyticRuleVersion5]" }, @@ -4116,6 +5482,11 @@ "contentId": "[variables('_SummarizeWebSessionData')]", "version": "[variables('playbookVersion1')]" }, + { + "kind": "Playbook", + "contentId": "[variables('_SummarizeWebSessionData_logingestion')]", + "version": "[variables('playbookVersion2')]" + }, { "kind": "Solution", "contentId": "azuresentinel.azure-sentinel-solution-paloaltopanos" diff --git a/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData/azuredeploy.json b/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData/azuredeploy.json index 6590523a616..b9fee898b65 100644 --- a/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData/azuredeploy.json +++ b/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData/azuredeploy.json @@ -2,13 +2,14 @@ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "metadata": { - "title": "Summarize Web Session Data", - "description": "The 'SummarizeWebSessionData' Playbook helps with summarizing the Web Session logs and ingesting them into custom tables for persistence. Although enabling the summarization playbook for the Web Session solution is totally optional, we highly recommend enabling it for a better user experience in environments with high EPS (events per second) data ingestion. After installing the solution, it will be deployed under Playbook Templates in the Automation blade of Microsoft Sentinel. It can be configured and managed from the Manage Solution view in Content Hub. This playbook will create four custom data summarization tables: WebSession_Summarized_SrcInfo_CL, WebSession_Summarized_SrcIP_CL, WebSession_Summarized_DstIP_CL and WebSession_Summarized_ThreatInfo_CL.", + "title": "[Deprecated] Summarize Web Session Data", + "description": "The 'SummarizeWebSessionData' Playbook helps with summarizing the Web Session logs and ingesting them into custom tables for persistence. Although enabling the summarization playbook for the Web Session solution is totally optional, we highly recommend enabling it for a better user experience in environments with high EPS (events per second) data ingestion. After installing the solution, it will be deployed under Playbook Templates in the Automation blade of Microsoft Sentinel. It can be configured and managed from the Manage Solution view in Content Hub. This playbook will create four custom data summarization tables: WebSession_Summarized_SrcInfo_CL, WebSession_Summarized_SrcIP_CL, WebSession_Summarized_DstIP_CL and WebSession_Summarized_ThreatInfo_CL. \n **NOTE: It uses the legacy HTTP data collector API to ingest the data, which is about to be deprecated, so it is recommended to use the SummarizeWebSessionData_logingestion playbook instead.**", "prerequisites": [], "postDeployment": [ "Authorize 'Azure Monitor Logs' and 'Azure Log Analytics Data Collector' API connections." ], "prerequisitesDeployTemplateFile": [], + "lastUpdateTime": "2026-09-02T00:00:00.000Z", "entities": [], "tags": ["Networking"], "support": { @@ -681,7 +682,7 @@ "identity": { "type": "SystemAssigned" }, - "apiVersion": "2017-07-01", + "apiVersion": "2019-05-01", "dependsOn": [ "[resourceId('Microsoft.Web/connections', variables('AzureloganalyticsdatacollectorConnectionName'))]", "[resourceId('Microsoft.Web/connections', variables('AzuremonitorlogsConnectionName'))]" diff --git a/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData/readme.md b/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData/readme.md index a63fa3da4dd..afaebdc7c94 100644 --- a/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData/readme.md +++ b/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData/readme.md @@ -12,7 +12,7 @@ This logic app helps to ingest summarized web session data into custom tables. P ### Deployment instructions 1. Deploy the playbook by clicking on "Deploy to Azure" button. This will take you to deploying an ARM Template wizard. [![Deploy to Azure](https://aka.ms/deploytoazurebutton)](https://aka.ms/deploywebsessionDataSummarizationPlaybookPublic) -[![Deploy to Azure Gov](https://aka.ms/deploytoazuregovbutton)](https://aka.ms/deploywebsessionDataSummarizationPlaybookGov) +[![Deploy to Azure Gov](https://aka.ms/deploytoazuregovernbutton)](https://aka.ms/deploywebsessionDataSummarizationPlaybookGov) 2. Fill in the required parameter: * Playbook Name: Enter the playbook name here (Ex: SummarizeWebSessionData) diff --git a/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData_logingestion/azuredeploy.json b/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData_logingestion/azuredeploy.json new file mode 100644 index 00000000000..2bb837c12d6 --- /dev/null +++ b/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData_logingestion/azuredeploy.json @@ -0,0 +1,781 @@ +{ + "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", + "contentVersion": "1.0.0.0", + "metadata": { + "title": "Summarize Web Session Data using Log Ingestion API", + "description": "The 'SummarizeWebSessionData' Playbook helps with summarizing the Web Session logs and ingesting them into custom tables for persistence. Although enabling the summarization playbook for the Web Session solution is totally optional, we highly recommend enabling it for a better user experience in environments with high EPS (events per second) data ingestion. After installing the solution, it will be deployed under Playbook Templates in the Automation blade of Microsoft Sentinel. It can be configured and managed from the Manage Solution view in Content Hub. This playbook will create four custom data summarization tables: WebSession_Summarized_SrcInfoV1_CL, WebSession_Summarized_SrcIPV1_CL, WebSession_Summarized_DstIPV1_CL and WebSession_Summarized_ThreatInfoV1_CL.", + "prerequisites": [], + "postDeployment": [ + "Authorize the 'Azure Monitor Logs' API connection. Log ingestion uses the playbook's managed identity." + ], + "prerequisitesDeployTemplateFile": [], + "lastUpdateTime": "2026-09-02T00:00:00.000Z", + "entities": [], + "tags": ["Networking"], + "support": { + "tier": "Microsoft" + }, + "author": { + "name": "Microsoft" + } + }, + "parameters": { + "PlaybookName": { + "defaultValue": "SummarizeWebSessionData-logingestion", + "type": "string" + }, + "logAnalyticsName": { + "type": "string", + "metadata": { + "description": "Enter value for logAnalyticsName" + } + }, + "resourceGroupName": { + "type": "string", + "metadata": { + "description": "Enter value for resourceGroupName" + } + }, + "subscriptionId": { + "type": "string", + "metadata": { + "description": "Enter value for subscriptionId" + } + } + }, + "variables": { + "AzuremonitorlogsConnectionName": "[concat('Azuremonitorlogs-', parameters('PlaybookName'))]", + "suffix": "[uniqueString(resourceId(parameters('subscriptionId'), parameters('resourceGroupName'), 'Microsoft.OperationalInsights/workspaces', parameters('logAnalyticsName')))]", + "DCEName": "[concat('web-session-summarization-dce-', variables('suffix'))]", + "DCRName": "[concat('web-session-summarization-dcr-', variables('suffix'))]", + "workspaceResourceId": "[resourceId(parameters('subscriptionId'), parameters('resourceGroupName'), 'Microsoft.OperationalInsights/workspaces', parameters('logAnalyticsName'))]", + "destinationName": "[concat('webSessionSummarizationDestination', variables('suffix'))]", + "monitoringMetricsPublisherRoleId": "3913510d-42f4-4e42-8a64-420c390055eb", + "roleAssignmentName": "[guid(resourceId('Microsoft.Insights/dataCollectionRules', variables('DCRName')), resourceId('Microsoft.Logic/workflows', parameters('PlaybookName')), variables('monitoringMetricsPublisherRoleId'))]" + }, + "resources": [ + { + "type": "Microsoft.Insights/dataCollectionEndpoints", + "apiVersion": "2022-06-01", + "name": "[variables('DCEName')]", + "location": "[resourceGroup().location]", + "kind": "Linux", + "properties": { + "description": "Data collection endpoint for Web Session Essentials summarized logs", + "networkAcls": { "publicNetworkAccess": "Enabled" } + } + }, + { + "type": "Microsoft.OperationalInsights/workspaces/tables", + "apiVersion": "2022-10-01", + "name": "[concat(parameters('logAnalyticsName'), '/WebSession_Summarized_DstIPV1_CL')]", + "properties": { "plan": "Analytics", "schema": { "name": "WebSession_Summarized_DstIPV1_CL", "columns": [ { "name": "SrcBytes_d", "type": "real" }, { "name": "DstBytes_d", "type": "real" }, { "name": "EventCount_d", "type": "real" }, { "name": "DstIpAddr_s", "type": "string" }, { "name": "SrcIPIsPrivate_b", "type": "boolean" }, { "name": "DstPortNumber_d", "type": "real" }, { "name": "DestDomain_s", "type": "string" }, { "name": "DstHostname_s", "type": "string" }, { "name": "EventResult_s", "type": "string" }, { "name": "EventResultDetails_s", "type": "string" }, { "name": "EventProduct_s", "type": "string" }, { "name": "EventType_s", "type": "string" }, { "name": "TimeGenerated", "type": "datetime" }, { "name": "EventTime_t", "type": "datetime" } ] } } + }, + { + "type": "Microsoft.OperationalInsights/workspaces/tables", + "apiVersion": "2022-10-01", + "name": "[concat(parameters('logAnalyticsName'), '/WebSession_Summarized_SrcInfoV1_CL')]", + "properties": { "plan": "Analytics", "schema": { "name": "WebSession_Summarized_SrcInfoV1_CL", "columns": [ { "name": "SrcBytes_d", "type": "real" }, { "name": "DstBytes_d", "type": "real" }, { "name": "EventCount_d", "type": "real" }, { "name": "HttpUserAgent_s", "type": "string" }, { "name": "EventResultDetails_s", "type": "string" }, { "name": "EventResult_s", "type": "string" }, { "name": "UrlCategory_s", "type": "string" }, { "name": "NetworkApplicationProtocol_s", "type": "string" }, { "name": "HttpRequestMethod_s", "type": "string" }, { "name": "HttpContentType_s", "type": "string" }, { "name": "EventProduct_s", "type": "string" }, { "name": "EventVendor_s", "type": "string" }, { "name": "EventType_s", "type": "string" }, { "name": "TimeGenerated", "type": "datetime" }, { "name": "EventTime_t", "type": "datetime" } ] } } + }, + { + "type": "Microsoft.OperationalInsights/workspaces/tables", + "apiVersion": "2022-10-01", + "name": "[concat(parameters('logAnalyticsName'), '/WebSession_Summarized_SrcIPV1_CL')]", + "properties": { "plan": "Analytics", "schema": { "name": "WebSession_Summarized_SrcIPV1_CL", "columns": [ { "name": "SrcBytes_d", "type": "real" }, { "name": "DstBytes_d", "type": "real" }, { "name": "EventCount_d", "type": "real" }, { "name": "SrcUsername_s", "type": "string" }, { "name": "SrcIpAddr_s", "type": "string" }, { "name": "SrcHostname_s", "type": "string" }, { "name": "DstIPIsPrivate_b", "type": "boolean" }, { "name": "DestDomain_s", "type": "string" }, { "name": "EventResult_s", "type": "string" }, { "name": "EventResultDetails_s", "type": "string" }, { "name": "EventProduct_s", "type": "string" }, { "name": "EventType_s", "type": "string" }, { "name": "TimeGenerated", "type": "datetime" }, { "name": "EventTime_t", "type": "datetime" } ] } } + }, + { + "type": "Microsoft.OperationalInsights/workspaces/tables", + "apiVersion": "2022-10-01", + "name": "[concat(parameters('logAnalyticsName'), '/WebSession_Summarized_ThreatInfoV1_CL')]", + "properties": { "plan": "Analytics", "schema": { "name": "WebSession_Summarized_ThreatInfoV1_CL", "columns": [ { "name": "EventCount_d", "type": "real" }, { "name": "ThreatName_s", "type": "string" }, { "name": "ThreatCategory_s", "type": "string" }, { "name": "ThreatRiskLevel_d", "type": "real" }, { "name": "ThreatOriginalConfidence_d", "type": "real" }, { "name": "EventSeverity_s", "type": "string" }, { "name": "ThreatField_s", "type": "string" }, { "name": "SrcIpAddr_s", "type": "string" }, { "name": "SrcUsername_s", "type": "string" }, { "name": "DestDomain_s", "type": "string" }, { "name": "EventResult_s", "type": "string" }, { "name": "DstIpAddr_s", "type": "string" }, { "name": "TimeGenerated", "type": "datetime" }, { "name": "EventTime_t", "type": "datetime" } ] } } + }, + { + "type": "Microsoft.Insights/dataCollectionRules", + "apiVersion": "2022-06-01", + "name": "[variables('DCRName')]", + "location": "[resourceGroup().location]", + "dependsOn": [ "[resourceId('Microsoft.Insights/dataCollectionEndpoints', variables('DCEName'))]", "[resourceId('Microsoft.OperationalInsights/workspaces/tables', parameters('logAnalyticsName'), 'WebSession_Summarized_DstIPV1_CL')]", "[resourceId('Microsoft.OperationalInsights/workspaces/tables', parameters('logAnalyticsName'), 'WebSession_Summarized_SrcInfoV1_CL')]", "[resourceId('Microsoft.OperationalInsights/workspaces/tables', parameters('logAnalyticsName'), 'WebSession_Summarized_SrcIPV1_CL')]", "[resourceId('Microsoft.OperationalInsights/workspaces/tables', parameters('logAnalyticsName'), 'WebSession_Summarized_ThreatInfoV1_CL')]" ], + "properties": { + "dataCollectionEndpointId": "[resourceId('Microsoft.Insights/dataCollectionEndpoints', variables('DCEName'))]", + "streamDeclarations": { + "Custom-WebSession_Summarized_DstIPV1": { "columns": [ { "name": "SrcBytes", "type": "real" }, { "name": "DstBytes", "type": "real" }, { "name": "EventCount", "type": "real" }, { "name": "DstIpAddr", "type": "string" }, { "name": "SrcIPIsPrivate", "type": "boolean" }, { "name": "DstPortNumber", "type": "real" }, { "name": "DestDomain", "type": "string" }, { "name": "DstHostname", "type": "string" }, { "name": "EventResult", "type": "string" }, { "name": "EventResultDetails", "type": "string" }, { "name": "EventProduct", "type": "string" }, { "name": "EventType", "type": "string" }, { "name": "TimeGenerated", "type": "datetime" }, { "name": "EventTime", "type": "datetime" } ] }, + "Custom-WebSession_Summarized_SrcInfoV1": { "columns": [ { "name": "SrcBytes", "type": "real" }, { "name": "DstBytes", "type": "real" }, { "name": "EventCount", "type": "real" }, { "name": "HttpUserAgent", "type": "string" }, { "name": "EventResultDetails", "type": "string" }, { "name": "EventResult", "type": "string" }, { "name": "UrlCategory", "type": "string" }, { "name": "NetworkApplicationProtocol", "type": "string" }, { "name": "HttpRequestMethod", "type": "string" }, { "name": "HttpContentType", "type": "string" }, { "name": "EventProduct", "type": "string" }, { "name": "EventVendor", "type": "string" }, { "name": "EventType", "type": "string" }, { "name": "TimeGenerated", "type": "datetime" }, { "name": "EventTime", "type": "datetime" } ] }, + "Custom-WebSession_Summarized_SrcIPV1": { "columns": [ { "name": "SrcBytes", "type": "real" }, { "name": "DstBytes", "type": "real" }, { "name": "EventCount", "type": "real" }, { "name": "SrcUsername", "type": "string" }, { "name": "SrcIpAddr", "type": "string" }, { "name": "SrcHostname", "type": "string" }, { "name": "DstIPIsPrivate", "type": "boolean" }, { "name": "DestDomain", "type": "string" }, { "name": "EventResult", "type": "string" }, { "name": "EventResultDetails", "type": "string" }, { "name": "EventProduct", "type": "string" }, { "name": "EventType", "type": "string" }, { "name": "TimeGenerated", "type": "datetime" }, { "name": "EventTime", "type": "datetime" } ] }, + "Custom-WebSession_Summarized_ThreatInfoV1": { "columns": [ { "name": "EventCount", "type": "real" }, { "name": "ThreatName", "type": "string" }, { "name": "ThreatCategory", "type": "string" }, { "name": "ThreatRiskLevel", "type": "real" }, { "name": "ThreatOriginalConfidence", "type": "real" }, { "name": "EventSeverity", "type": "string" }, { "name": "ThreatField", "type": "string" }, { "name": "SrcIpAddr", "type": "string" }, { "name": "SrcUsername", "type": "string" }, { "name": "DestDomain", "type": "string" }, { "name": "EventResult", "type": "string" }, { "name": "DstIpAddr", "type": "string" }, { "name": "TimeGenerated", "type": "datetime" }, { "name": "EventTime", "type": "datetime" } ] } + }, + "destinations": { "logAnalytics": [ { "workspaceResourceId": "[variables('workspaceResourceId')]", "name": "[variables('destinationName')]" } ] }, + "dataFlows": [ + { "streams": [ "Custom-WebSession_Summarized_DstIPV1" ], "destinations": [ "[variables('destinationName')]" ], "transformKql": "source | project SrcBytes_d=toreal(SrcBytes), DstBytes_d=toreal(DstBytes), EventCount_d=toreal(EventCount), DstIpAddr_s=tostring(DstIpAddr), SrcIPIsPrivate_b=tobool(SrcIPIsPrivate), DstPortNumber_d=toreal(DstPortNumber), DestDomain_s=tostring(DestDomain), DstHostname_s=tostring(DstHostname), EventResult_s=tostring(EventResult), EventResultDetails_s=tostring(EventResultDetails), EventProduct_s=tostring(EventProduct), EventType_s=tostring(EventType), TimeGenerated=todatetime(TimeGenerated), EventTime_t=todatetime(EventTime)", "outputStream": "Custom-WebSession_Summarized_DstIPV1_CL" }, + { "streams": [ "Custom-WebSession_Summarized_SrcInfoV1" ], "destinations": [ "[variables('destinationName')]" ], "transformKql": "source | project SrcBytes_d=toreal(SrcBytes), DstBytes_d=toreal(DstBytes), EventCount_d=toreal(EventCount), HttpUserAgent_s=tostring(HttpUserAgent), EventResultDetails_s=tostring(EventResultDetails), EventResult_s=tostring(EventResult), UrlCategory_s=tostring(UrlCategory), NetworkApplicationProtocol_s=tostring(NetworkApplicationProtocol), HttpRequestMethod_s=tostring(HttpRequestMethod), HttpContentType_s=tostring(HttpContentType), EventProduct_s=tostring(EventProduct), EventVendor_s=tostring(EventVendor), EventType_s=tostring(EventType), TimeGenerated=todatetime(TimeGenerated), EventTime_t=todatetime(EventTime)", "outputStream": "Custom-WebSession_Summarized_SrcInfoV1_CL" }, + { "streams": [ "Custom-WebSession_Summarized_SrcIPV1" ], "destinations": [ "[variables('destinationName')]" ], "transformKql": "source | project SrcBytes_d=toreal(SrcBytes), DstBytes_d=toreal(DstBytes), EventCount_d=toreal(EventCount), SrcUsername_s=tostring(SrcUsername), SrcIpAddr_s=tostring(SrcIpAddr), SrcHostname_s=tostring(SrcHostname), DstIPIsPrivate_b=tobool(DstIPIsPrivate), DestDomain_s=tostring(DestDomain), EventResult_s=tostring(EventResult), EventResultDetails_s=tostring(EventResultDetails), EventProduct_s=tostring(EventProduct), EventType_s=tostring(EventType), TimeGenerated=todatetime(TimeGenerated), EventTime_t=todatetime(EventTime)", "outputStream": "Custom-WebSession_Summarized_SrcIPV1_CL" }, + { "streams": [ "Custom-WebSession_Summarized_ThreatInfoV1" ], "destinations": [ "[variables('destinationName')]" ], "transformKql": "source | project EventCount_d=toreal(EventCount), ThreatName_s=tostring(ThreatName), ThreatCategory_s=tostring(ThreatCategory), ThreatRiskLevel_d=toreal(ThreatRiskLevel), ThreatOriginalConfidence_d=toreal(ThreatOriginalConfidence), EventSeverity_s=tostring(EventSeverity), ThreatField_s=tostring(ThreatField), SrcIpAddr_s=tostring(SrcIpAddr), SrcUsername_s=tostring(SrcUsername), DestDomain_s=tostring(DestDomain), EventResult_s=tostring(EventResult), DstIpAddr_s=tostring(DstIpAddr), TimeGenerated=todatetime(TimeGenerated), EventTime_t=todatetime(EventTime)", "outputStream": "Custom-WebSession_Summarized_ThreatInfoV1_CL" } + ] + } + }, + { + "properties": { + "provisioningState": "Succeeded", + "state": "Disabled", + "definition": { + "$schema": "https://schema.management.azure.com/providers/Microsoft.Logic/schemas/2016-06-01/workflowdefinition.json#", + "contentVersion": "1.0.0.0", + "parameters": { + "$connections": { + "defaultValue": { + }, + "type": "Object" + }, + "logAnalyticsName": { + "defaultValue": "[parameters('logAnalyticsName')]", + "type": "string" + }, + "resourceGroupName": { + "defaultValue": "[parameters('resourceGroupName')]", + "type": "string" + }, + "subscriptionId": { + "defaultValue": "[parameters('subscriptionId')]", + "type": "string" + }, + "ingestionEndpoint": { + "defaultValue": "[concat(reference(resourceId('Microsoft.Insights/dataCollectionEndpoints', variables('DCEName'))).logsIngestion.endpoint, '/dataCollectionRules/', reference(resourceId('Microsoft.Insights/dataCollectionRules', variables('DCRName'))).immutableId, '/streams/')]", + "type": "string" + } + }, + "triggers": { + "Recurrence": { + "recurrence": { + "frequency": "Hour", + "interval": 1 + }, + "evaluatedRecurrence": { + "frequency": "Hour", + "interval": 1 + }, + "type": "Recurrence" + } + }, + "actions": { + "Condition_DstIP": { + "actions": { + "For_each_DstIP": { + "foreach": "@variables('multipleArraysDstIP')", + "actions": { + "Send_Data_DstIP": { + "runAfter": { + }, + "type": "Http", + "inputs": { + "body": "@items('For_each_DstIP')", + "headers": { + "Content-Type": "application/json" + }, + "authentication": { + "type": "ManagedServiceIdentity", + "audience": "https://monitor.azure.com/" + }, + "method": "POST", + "uri": "@concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_DstIPV1', '?api-version=2023-01-01')" + } + } + }, + "runAfter": { + "Set_variable_-_multipleArraysDstIP": [ + "Succeeded" + ] + }, + "type": "Foreach" + }, + "Set_variable_-_multipleArraysDstIP": { + "runAfter": { + }, + "type": "SetVariable", + "inputs": { + "name": "multipleArraysDstIP", + "value": "@chunk(body('Run_query_and_list_results_DstIP')?['value'],div(variables('MaxByteSizeAllowed'),div(variables('TotalCharacterLengthDstIP'),variables('ArraySizeDstIP'))))" + } + } + }, + "runAfter": { + "Initialize_variable_-_multipleArraysDstIP": [ + "Succeeded" + ] + }, + "expression": { + "and": [ + { + "greater": [ + "@variables('ArraySizeDstIP')", + 0 + ] + } + ] + }, + "type": "If" + }, + "Condition_SourceInfo": { + "actions": { + "For_each_-_SubArray_-_SourceInfo": { + "foreach": "@variables('multipleArraysSourceInfo')", + "actions": { + "Send_Data_SourceInfo": { + "runAfter": { + }, + "type": "Http", + "inputs": { + "body": "@items('For_each_-_SubArray_-_SourceInfo')", + "headers": { + "Content-Type": "application/json" + }, + "authentication": { + "type": "ManagedServiceIdentity", + "audience": "https://monitor.azure.com/" + }, + "method": "POST", + "uri": "@concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_SrcInfoV1', '?api-version=2023-01-01')" + } + } + }, + "runAfter": { + "Set_variable": [ + "Succeeded" + ] + }, + "type": "Foreach" + }, + "Set_variable": { + "runAfter": { + }, + "type": "SetVariable", + "inputs": { + "name": "multipleArraysSourceInfo", + "value": "@chunk(body('Run_query_and_list_results_SourceInfo')?['value'],div(variables('MaxByteSizeAllowed'),div(variables('TotalCharacterLengthSourceInfo'),variables('ArraySizeSourceInfo'))))" + } + } + }, + "runAfter": { + "Initialize_variable_-_multipleArrays_-_SourceInfo": [ + "Succeeded" + ] + }, + "expression": { + "and": [ + { + "greater": [ + "@variables('ArraySizeSourceInfo')", + 0 + ] + } + ] + }, + "type": "If" + }, + "Condition_SrcIP": { + "actions": { + "For_each": { + "foreach": "@variables('multipleArraysSrcIP')", + "actions": { + "Send_Data_SrcIP": { + "runAfter": { + }, + "type": "Http", + "inputs": { + "body": "@items('For_each')", + "headers": { + "Content-Type": "application/json" + }, + "authentication": { + "type": "ManagedServiceIdentity", + "audience": "https://monitor.azure.com/" + }, + "method": "POST", + "uri": "@concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_SrcIPV1', '?api-version=2023-01-01')" + } + } + }, + "runAfter": { + "Set_variable_multipleArraysIP": [ + "Succeeded" + ] + }, + "type": "Foreach" + }, + "Set_variable_multipleArraysIP": { + "runAfter": { + }, + "type": "SetVariable", + "inputs": { + "name": "multipleArraysSrcIP", + "value": "@chunk(body('Run_query_and_list_results_SrcIP')?['value'],div(variables('MaxByteSizeAllowed'),div(variables('TotalCharacterLengthSrcIP'),variables('ArraySizeSrcIP'))))" + } + } + }, + "runAfter": { + "Initialize_variable_-_multipleArraysSrcIP": [ + "Succeeded" + ] + }, + "expression": { + "and": [ + { + "greater": [ + "@variables('ArraySizeSrcIP')", + 0 + ] + } + ] + }, + "type": "If" + }, + "Condition_ThreatInfo": { + "actions": { + "For_each_ThreatInfo": { + "foreach": "@variables('multipleArraysThreatInfo')", + "actions": { + "Send_Data": { + "runAfter": { + }, + "type": "Http", + "inputs": { + "body": "@items('For_each_ThreatInfo')", + "headers": { + "Content-Type": "application/json" + }, + "authentication": { + "type": "ManagedServiceIdentity", + "audience": "https://monitor.azure.com/" + }, + "method": "POST", + "uri": "@concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_ThreatInfoV1', '?api-version=2023-01-01')" + } + } + }, + "runAfter": { + "Set_variable_-_multipleArraysThreatInfo": [ + "Succeeded" + ] + }, + "type": "Foreach" + }, + "Set_variable_-_multipleArraysThreatInfo": { + "runAfter": { + }, + "type": "SetVariable", + "inputs": { + "name": "multipleArraysThreatInfo", + "value": "@chunk(body('Run_query_and_list_results_ThreatInfo')?['value'],div(variables('MaxByteSizeAllowed'),div(variables('TotalCharacterLengthThreatInfo'),variables('ArraySizeThreatInfo'))))" + } + } + }, + "runAfter": { + "Initialize_variable_-_multipleArraysThreatInfo": [ + "Succeeded" + ] + }, + "expression": { + "and": [ + { + "greater": [ + "@variables('ArraySizeThreatInfo')", + 0 + ] + } + ] + }, + "type": "If" + }, + "Initialize_variable_-_ArraySizeDstIP": { + "runAfter": { + "Run_query_and_list_results_DstIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "ArraySizeDstIP", + "type": "integer", + "value": "@length(body('Run_query_and_list_results_DstIP')?['value'])" + } + ] + } + }, + "Initialize_variable_-_ArraySizeSrcIP": { + "runAfter": { + "Run_query_and_list_results_SrcIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "ArraySizeSrcIP", + "type": "integer", + "value": "@length(body('Run_query_and_list_results_SrcIP')?['value'])" + } + ] + } + }, + "Initialize_variable_-_ArraySizeThreatInfo": { + "runAfter": { + "Run_query_and_list_results_ThreatInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "ArraySizeThreatInfo", + "type": "integer", + "value": "@length(body('Run_query_and_list_results_ThreatInfo')?['value'])" + } + ] + } + }, + "Initialize_variable_-_ArraySize_-_SourceInfo": { + "runAfter": { + "Run_query_and_list_results_SourceInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "ArraySizeSourceInfo", + "type": "integer", + "value": "@length(body('Run_query_and_list_results_SourceInfo')?['value'])" + } + ] + } + }, + "Initialize_variable_-_TotalCharacterLengthSrcIP": { + "runAfter": { + "Initialize_variable_-_ArraySizeSrcIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "TotalCharacterLengthSrcIP", + "type": "integer", + "value": "@length(string(body('Run_query_and_list_results_SrcIP')?['value']))" + } + ] + } + }, + "Initialize_variable_-_TotalCharacterLengthThreatInfo": { + "runAfter": { + "Initialize_variable_-_ArraySizeThreatInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "TotalCharacterLengthThreatInfo", + "type": "integer", + "value": "@length(string(body('Run_query_and_list_results_ThreatInfo')?['value']))" + } + ] + } + }, + "Initialize_variable_-_TotalCharacterLength_-_SourceInfo": { + "runAfter": { + "Initialize_variable_-_ArraySize_-_SourceInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "TotalCharacterLengthSourceInfo", + "type": "integer", + "value": "@length(string(body('Run_query_and_list_results_SourceInfo')?['value']))" + } + ] + } + }, + "Initialize_variable_-_TotalCharaterLengthDstIP": { + "runAfter": { + "Initialize_variable_-_ArraySizeDstIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "TotalCharacterLengthDstIP", + "type": "integer", + "value": "@length(string(body('Run_query_and_list_results_DstIP')?['value']))" + } + ] + } + }, + "Initialize_variable_-_multipleArraysDstIP": { + "runAfter": { + "Initialize_variable_-_TotalCharaterLengthDstIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "multipleArraysDstIP", + "type": "array" + } + ] + } + }, + "Initialize_variable_-_multipleArraysSrcIP": { + "runAfter": { + "Initialize_variable_-_TotalCharacterLengthSrcIP": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "multipleArraysSrcIP", + "type": "array" + } + ] + } + }, + "Initialize_variable_-_multipleArraysThreatInfo": { + "runAfter": { + "Initialize_variable_-_TotalCharacterLengthThreatInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "multipleArraysThreatInfo", + "type": "array" + } + ] + } + }, + "Initialize_variable_-_multipleArrays_-_SourceInfo": { + "runAfter": { + "Initialize_variable_-_TotalCharacterLength_-_SourceInfo": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "multipleArraysSourceInfo", + "type": "array" + } + ] + } + }, + "MaxRequestSizeAllowed": { + "runAfter": { + "nowTime": [ + "Succeeded" + ] + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "MaxByteSizeAllowed", + "type": "integer", + "value": 26214400 + } + ] + } + }, + "Run_query_and_list_results_DstIP": { + "runAfter": { + "MaxRequestSizeAllowed": [ + "Succeeded" + ] + }, + "type": "ApiConnection", + "inputs": { + "body": "let nowTime = todatetime(\"@{variables('nowTime')}\");\nlet lastRecievedTime = toscalar (\n union isfuzzy=true\n (\n WebSession_Summarized_DstIPV1_CL \n | summarize max(EventTime_t)\n | extend max_TimeGenerated = datetime_add('hour',1,bin(max_EventTime_t,1h))\n ),\n (\n print (nowTime)\n | extend max_TimeGenerated = datetime_add('day',-1,bin(print_0,1h)) \n | project-away print_0\n )\n | summarize max(max_TimeGenerated)\n );\n_Im_WebSession(starttime=lastRecievedTime,endtime=bin(nowTime,1h))\n| where TimeGenerated \u003c bin(nowTime,1h)\n| summarize SrcBytes = sum(SrcBytes), DstBytes = sum(DstBytes), EventCount = count() by DstIpAddr, SrcIPIsPrivate = ipv4_is_private(SrcIpAddr), DstPortNumber, DestDomain = tostring(parse_url(Url)[\"Host\"]), DstHostname, EventResult, EventResultDetails, EventProduct, EventType, bin(TimeGenerated,1h)\n| extend EventTime = TimeGenerated", + "host": { + "connection": { + "name": "@parameters('$connections')['azuremonitorlogs']['connectionId']" + } + }, + "method": "post", + "path": "/queryData", + "queries": { + "resourcegroups": "@parameters('resourceGroupName')", + "resourcename": "@parameters('logAnalyticsName')", + "resourcetype": "Log Analytics Workspace", + "subscriptions": "@parameters('subscriptionId')", + "timerange": "Last 1 day" + } + } + }, + "Run_query_and_list_results_SourceInfo": { + "runAfter": { + "MaxRequestSizeAllowed": [ + "Succeeded" + ] + }, + "type": "ApiConnection", + "inputs": { + "body": "let nowTime = todatetime(\"@{variables('nowTime')}\");\nlet lastRecievedTime = toscalar (\n union isfuzzy=true\n (\n WebSession_Summarized_SrcInfoV1_CL \n | summarize max(EventTime_t)\n | extend max_TimeGenerated = datetime_add('hour',1,bin(max_EventTime_t,1h))\n ),\n (\n print (nowTime)\n | extend max_TimeGenerated = datetime_add('day',-1,bin(print_0,1h)) \n | project-away print_0\n )\n | summarize max(max_TimeGenerated)\n );\n_Im_WebSession(starttime=lastRecievedTime,endtime=bin(nowTime,1h))\n| where TimeGenerated \u003c bin(nowTime,1h)\n| summarize SrcBytes = sum(SrcBytes), DstBytes = sum(DstBytes), EventCount = count() by HttpUserAgent, EventResultDetails, EventResult, UrlCategory, NetworkApplicationProtocol, HttpRequestMethod, HttpContentType, EventTime = bin(TimeGenerated, 1h), EventProduct, EventVendor, EventType, bin(TimeGenerated,1h)\n| extend EventTime = TimeGenerated", + "host": { + "connection": { + "name": "@parameters('$connections')['azuremonitorlogs']['connectionId']" + } + }, + "method": "post", + "path": "/queryData", + "queries": { + "resourcegroups": "@parameters('resourceGroupName')", + "resourcename": "@parameters('logAnalyticsName')", + "resourcetype": "Log Analytics Workspace", + "subscriptions": "@parameters('subscriptionId')", + "timerange": "Last 1 day" + } + } + }, + "Run_query_and_list_results_SrcIP": { + "runAfter": { + "MaxRequestSizeAllowed": [ + "Succeeded" + ] + }, + "type": "ApiConnection", + "inputs": { + "body": "let nowTime = todatetime(\"@{variables('nowTime')}\");\nlet lastRecievedTime = toscalar (\n union isfuzzy=true\n (\n WebSession_Summarized_SrcIPV1_CL \n | summarize max(EventTime_t)\n | extend max_TimeGenerated = datetime_add('hour',1,bin(max_EventTime_t,1h))\n ),\n (\n print (nowTime)\n | extend max_TimeGenerated = datetime_add('day',-1,bin(print_0,1h)) \n | project-away print_0\n )\n | summarize max(max_TimeGenerated)\n );\n_Im_WebSession(starttime=lastRecievedTime,endtime=bin(nowTime,1h))\n| where TimeGenerated \u003c bin(nowTime,1h)\n| summarize SrcBytes = sum(SrcBytes), DstBytes = sum(DstBytes), EventCount = count() by SrcUsername, SrcIpAddr, SrcHostname, DstIPIsPrivate = ipv4_is_private(DstIpAddr), DestDomain = tostring(parse_url(Url)[\"Host\"]), EventResult, EventResultDetails, EventProduct, EventType, bin(TimeGenerated,1h)\n| extend EventTime = TimeGenerated", + "host": { + "connection": { + "name": "@parameters('$connections')['azuremonitorlogs']['connectionId']" + } + }, + "method": "post", + "path": "/queryData", + "queries": { + "resourcegroups": "@parameters('resourceGroupName')", + "resourcename": "@parameters('logAnalyticsName')", + "resourcetype": "Log Analytics Workspace", + "subscriptions": "@parameters('subscriptionId')", + "timerange": "Last 1 day" + } + } + }, + "Run_query_and_list_results_ThreatInfo": { + "runAfter": { + "MaxRequestSizeAllowed": [ + "Succeeded" + ] + }, + "type": "ApiConnection", + "inputs": { + "body": "let nowTime = todatetime(\"@{variables('nowTime')}\");\nlet lastRecievedTime = toscalar (\n union isfuzzy=true\n (\n WebSession_Summarized_ThreatInfoV1_CL \n | summarize max(EventTime_t)\n | extend max_TimeGenerated = datetime_add('hour',1,bin(max_EventTime_t,1h))\n ),\n (\n print (nowTime)\n | extend max_TimeGenerated = datetime_add('day',-1,bin(print_0,1h)) \n | project-away print_0\n )\n | summarize max(max_TimeGenerated)\n );\n_Im_WebSession(starttime=lastRecievedTime,endtime=bin(nowTime,1h))\n| where TimeGenerated \u003c bin(nowTime,1h)\n| where (ThreatName != 'None' and isnotempty(ThreatName)) or (ThreatCategory != 'None' and isnotempty(ThreatCategory)) or ThreatRiskLevel \u003e 60 or toint(ThreatOriginalConfidence) \u003e 0 or EventSeverity in ('Medium','High') or isnotempty(ThreatField)\n| summarize EventCount=count() by ThreatName, ThreatCategory, ThreatRiskLevel, toint(ThreatOriginalConfidence), EventSeverity, ThreatField, SrcIpAddr, SrcUsername, DestDomain = tostring(parse_url(Url)[\"Host\"]), bin(TimeGenerated, 1h), EventResult, DstIpAddr\n| extend EventTime = TimeGenerated", + "host": { + "connection": { + "name": "@parameters('$connections')['azuremonitorlogs']['connectionId']" + } + }, + "method": "post", + "path": "/queryData", + "queries": { + "resourcegroups": "@parameters('resourceGroupName')", + "resourcename": "@parameters('logAnalyticsName')", + "resourcetype": "Log Analytics Workspace", + "subscriptions": "@parameters('subscriptionId')", + "timerange": "Last 1 day" + } + } + }, + "nowTime": { + "runAfter": { + }, + "type": "InitializeVariable", + "inputs": { + "variables": [ + { + "name": "nowTime", + "type": "string", + "value": "@{utcNow()}" + } + ] + } + } + }, + "outputs": { + } + }, + "parameters": { + "$connections": { + "value": { + "azuremonitorlogs": { + "connectionId": "[resourceId('Microsoft.Web/connections', variables('AzuremonitorlogsConnectionName'))]", + "connectionName": "[variables('AzuremonitorlogsConnectionName')]", + "id": "[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Web/locations/', resourceGroup().location, '/managedApis/Azuremonitorlogs')]" + } + } + } + } + }, + "name": "[parameters('PlaybookName')]", + "type": "Microsoft.Logic/workflows", + "location": "[resourceGroup().location]", + "tags": { + "hidden-SentinelTemplateName": "SummarizeWebSessionData", + "hidden-SentinelTemplateVersion": "1.0" + }, + "identity": { + "type": "SystemAssigned" + }, + "apiVersion": "2019-05-01", + "dependsOn": [ + "[resourceId('Microsoft.Insights/dataCollectionRules', variables('DCRName'))]", + "[resourceId('Microsoft.Web/connections', variables('AzuremonitorlogsConnectionName'))]" + ] + }, + { + "type": "Microsoft.Web/connections", + "apiVersion": "2016-06-01", + "name": "[variables('AzuremonitorlogsConnectionName')]", + "location": "[resourceGroup().location]", + "kind": "V1", + "properties": { + "displayName": "[variables('AzuremonitorlogsConnectionName')]", + "customParameterValues": { + }, + "api": { + "id": "[concat('/subscriptions/', subscription().subscriptionId, '/providers/Microsoft.Web/locations/', resourceGroup().location, '/managedApis/Azuremonitorlogs')]" + } + } + }, + { + "type": "Microsoft.Authorization/roleAssignments", + "apiVersion": "2022-04-01", + "name": "[variables('roleAssignmentName')]", + "scope": "[resourceId('Microsoft.Insights/dataCollectionRules', variables('DCRName'))]", + "dependsOn": [ + "[resourceId('Microsoft.Insights/dataCollectionRules', variables('DCRName'))]", + "[resourceId('Microsoft.Logic/workflows', parameters('PlaybookName'))]" + ], + "properties": { + "roleDefinitionId": "[subscriptionResourceId('Microsoft.Authorization/roleDefinitions', variables('monitoringMetricsPublisherRoleId'))]", + "principalId": "[reference(resourceId('Microsoft.Logic/workflows', parameters('PlaybookName')), '2019-05-01', 'Full').identity.principalId]", + "principalType": "ServicePrincipal" + } + } + ] +} diff --git a/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData_logingestion/readme.md b/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData_logingestion/readme.md new file mode 100644 index 00000000000..1870eebe06f --- /dev/null +++ b/Solutions/Web Session Essentials/Playbooks/SummarizeWebSessionData_logingestion/readme.md @@ -0,0 +1,39 @@ +# Web Session Essentials Summarization Capability + +This Logic App ingests summarized Web Session data into custom Log Analytics tables by using the Logs Ingestion API. Enabling this playbook incurs additional cost. + +## Summary + +The playbook improves Web Session Essentials solution performance by creating four tables containing analytics based on the ASIM Web Session schema: + +- `WebSession_Summarized_SrcInfoV1_CL` +- `WebSession_Summarized_SrcIPV1_CL` +- `WebSession_Summarized_DstIPV1_CL` +- `WebSession_Summarized_ThreatInfoV1_CL` + +The V1 table names avoid conflicts with existing classic tables. The playbook uses a data collection endpoint (DCE), data collection rule (DCR), and its managed identity to ingest summarized data. + +## Deployment Instructions + +1. Deploy the playbook by selecting the applicable button: + +[![Deploy to Azure](https://aka.ms/deploytoazurebutton)](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2F7c679ec0cbcbaf50c510bb534592e054a540983f%2FSolutions%2FWeb%2520Session%2520Essentials%2FPlaybooks%2FSummarizeWebSessionData_logingestion%2Fazuredeploy.json) +[![Deploy to Azure Gov](https://aka.ms/deploytoazuregovernbutton)](https://portal.azure.us/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2F7c679ec0cbcbaf50c510bb534592e054a540983f%2FSolutions%2FWeb%2520Session%2520Essentials%2FPlaybooks%2FSummarizeWebSessionData_logingestion%2Fazuredeploy.json) + +2. Deploy the playbook to a resource group in the same Azure region as the Log Analytics workspace. +3. Provide the required parameters: + - **Playbook Name**: The default is `SummarizeWebSessionData-logingestion`. + - **Log Analytics Name**: The Log Analytics workspace that contains the Web Session data. + - **Resource Group Name** and **Subscription ID**: The workspace resource group and subscription. + +The deployment creates the DCE, DCR, V1 custom tables, and grants the playbook managed identity the Monitoring Metrics Publisher role on the DCR. + +## Post-Deployment Instructions + +Authorize the Azure Monitor Logs API connection if prompted: + +1. Open the Azure Monitor Logs API connection. +2. Select **Edit API connection**. +3. Select **Authorize**, sign in, and then save the connection. + +The Logs Ingestion API uses the playbook's managed identity. No Azure Log Analytics Data Collector connection or workspace key is required. \ No newline at end of file diff --git a/Solutions/Web Session Essentials/ReleaseNotes.md b/Solutions/Web Session Essentials/ReleaseNotes.md index ff2418fd72c..fbf0605b90f 100644 --- a/Solutions/Web Session Essentials/ReleaseNotes.md +++ b/Solutions/Web Session Essentials/ReleaseNotes.md @@ -1,5 +1,6 @@ | **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** | |-------------|--------------------------------|-----------------------------------------------| +| 3.0.4 | 02-09-2026 | Added Summarize Web Session Data using Log Ingestion API **Playbook** | | 3.0.3 | 06-06-2024 | Updated Entity Mapping **Analytic Rule** CommandInURL.yaml | | 3.0.2 | 31-01-2024 | Updated the solution to fix **Analytic Rules** deployment issue | | 3.0.1 | 02-01-2024 | Tagged for dependent Solutions for deployment |