Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Add more operations and more efficient parsing in IPEntity_AzureFirewall.yaml

Open ep3p opened this issue 3 years ago • 15 comments

I have added more operations to compare, and I think clients should select which events they want this rule to trigger. Azure Firewall might add more operations in the long run. The clients can uncomment a specific line to exclude certain operations.

Please, could you check this query against a big dataset?

Change(s):

  • Changed the parsing of msg_s
  • Filter by Category, not by OperationName.

Reason for Change(s):

  • Azure Monitor has some queries for Azure Firewall events, with a more efficient parsing (I think).
  • With new capabilities, more operations might be added in Azure Firewall and we might want check those events, we don't want to limit ourselves.

Version Updated:

  • Yes

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

ep3p avatar Jun 12 '22 19:06 ep3p

@aprakash13 : Please review the detections.

v-spadarthi avatar Aug 08 '22 14:08 v-spadarthi

@aprakash13 : Please review the detections.

v-spadarthi avatar Sep 02 '22 07:09 v-spadarthi

@aprakash13 : Please review the detections.

v-spadarthi avatar Sep 07 '22 07:09 v-spadarthi

@aprakash13 : Please review the detections.

v-spadarthi avatar Sep 08 '22 07:09 v-spadarthi

@aprakash13 - We will not want to take these changes without chatting with our TI folks. Please discuss the changes with them.

shainw avatar Sep 11 '22 18:09 shainw

@shainw /@aprakash13 : Could you please review the detections and provide your signoff. Thanks!!

v-spadarthi avatar Sep 12 '22 11:09 v-spadarthi

@shainw /@aprakash13 : Could you please review the detections and provide your signoff. Thanks!!

@v-spadarthi - We will talk with our internal TI feature PMs on this one as stated above your request for review.

shainw avatar Sep 12 '22 14:09 shainw

@shainw /@aprakash13 :Could you please update the status if any ?

v-spadarthi avatar Sep 21 '22 06:09 v-spadarthi

@shainw /@aprakash13 :Could you please update the status if any ?

v-marimanda avatar Sep 22 '22 13:09 v-marimanda

Maybe you will prefer to add a new version that uses AZFW tables.

ep3p avatar Sep 22 '22 14:09 ep3p

@shainw /@aprakash13 :Could you please update the status if any ?

v-spadarthi avatar Sep 28 '22 04:09 v-spadarthi

@shainw /@aprakash13 :Could you please update the status if any ?

v-marimanda avatar Sep 30 '22 05:09 v-marimanda

@shainw /@aprakash13 :Could you please update the status if any ?

v-marimanda avatar Oct 07 '22 05:10 v-marimanda

@shainw /@aprakash13 :Could you please update the status if any ?

v-marimanda avatar Oct 11 '22 11:10 v-marimanda

@aprakash13 can you please take look and provide your update. thanks!!!

v-marimanda avatar Oct 14 '22 05:10 v-marimanda

Hi @shainw, It would be great if you could spare sometime on this and provide your update. Thanks

v-mchatla avatar Oct 18 '22 20:10 v-mchatla

@aprakash13 - We will not want to take these changes without chatting with our TI folks. Please discuss the changes with them.

Hi @shainw Can you please provide update on this. Thanks

v-mchatla avatar Oct 21 '22 05:10 v-mchatla

Hi @shainw Can you please provide update on this. Thanks

v-mchatla avatar Oct 25 '22 10:10 v-mchatla

@aprakash13 - We will not want to take these changes without chatting with our TI folks. Please discuss the changes with them.

Hi @shainw, This PR is pending from long back. It would be great if you can provide some update on this. Thanks

v-mchatla avatar Oct 28 '22 05:10 v-mchatla

@aprakash13 - We will not want to take these changes without chatting with our TI folks. Please discuss the changes with them.

Hi @shainw, This PR is pending from long back. It would be great if you can provide some update on this. Thanks

Hi @shainw, Requesting you to provide update on this as its pending from long back. Thanks

v-mchatla avatar Nov 02 '22 04:11 v-mchatla

Hi @shainw, Can you please review or assign it to someone who can help on this. Thanks

v-mchatla avatar Nov 04 '22 05:11 v-mchatla

Hi @shainw - Can you please review the PR and provide your signoff. Thanks

v-mchatla avatar Nov 08 '22 07:11 v-mchatla

Hi @aprakash13, Can you please get confirmation on this and provide update. Thanks

v-mchatla avatar Nov 10 '22 13:11 v-mchatla

Hi @aprakash13, Can you please provide update on this. Thanks

v-mchatla avatar Nov 16 '22 05:11 v-mchatla

Hi @aprakash13, Can you please provide update on this as it is pending from long back. Thanks

v-mchatla avatar Nov 18 '22 05:11 v-mchatla