Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Aliter Consulting SOD Reporting for Sentinel Threat Monitoring for SAP

Open gajackson1963 opened this issue 3 years ago • 61 comments

Required items, please complete

Change(s):

  • See guidance below

Reason for Change(s):

  • See guidance below

Version Updated:

  • Required only for Detections/Analytic Rule templates
  • See guidance below

Testing Completed:

  • See guidance below

Checked that the validations are passing and have addressed any issues that are present:

  • See guidance below

Guidance <- remove section before submitting


Before submitting this PR please ensure that you have read the following sections and filled out the changes, reason for change and testing complete sections:

Thank you for your contribution to the Microsoft Sentinel Github repo.

Details of the code changes in your submitted PR. Providing descriptions for pull requests ensures there is context to changes being made and greatly enhances the code review process. Providing associated Issues that this resolves also easily connects the reason.

Change(s):

  • Updated syntax for XYZ.yaml

Reason for Change(s):

  • New schema used for XYZ.yaml
  • Resolves ISSUE #1234

Version updated:

  • Yes
  • Detections/Analytic Rule templates are required to have the version updated

The code should have been tested in a Microsoft Sentinel environment that does not have any custom parsers, functions or tables, so that you validate no incorrect syntax and execution functions properly. If your submission requires a custom parser or function, it must be submitted with the PR.

Testing Completed:

  • Yes/No/Need Help

Note: If updating a detection, you must update the version field.

Before the submission has been made, please look at running the KQL and Yaml Validation Checks locally. https://github.com/Azure/Azure-Sentinel#run-kql-validation-locally

Checked that the validations are passing and have addressed any issues that are present:

  • Yes/No/Need Help

Note: Let us know if you have tried fixing the validation error and need help.

References:


gajackson1963 avatar Jul 18 '22 09:07 gajackson1963

CLA assistant check
All CLA requirements met.

ghost avatar Jul 18 '22 09:07 ghost

Hello - do you have an estimated time for this to be reviewed, please?

gajackson1963 avatar Jul 28 '22 14:07 gajackson1963

@gajackson1963 : Could you please resolve the below comments, While checking the workbook after deployment in our environment i'm seeing the empty workbook. It is mandatory for there are at least 4 charts / graphs in the workbook. If you want to add any images into your workbook please follow the process "previewImagesFileNames" includes location to the black and white png files and these are in the PR in the right locations Workbook\Images\Preview folder and also have the right names metadata name = the actual file names. There can be multiple dark and light background images for the same workbook and this can be represented in the format example [ "BarracudaWhite1.png", "BarracudaBlack1.png", "BarracudaWhite2.png", "BarracudaBlack2.png" ]

I have verified Logos/AliterConsulting.svg looks fine but, you can remove the AliterConsulting.svg file.

v-spadarthi avatar Jul 29 '22 10:07 v-spadarthi

Hello, when you say the workbook is empty, are you saying you're trying to analyse the data the workbook is designed for? The workbook has 2 charts and 2 graphs but data will only appear if you have Sentinel for SAP deployed and it's collecting data from the attached SAP systems. Please confirm. Also, not sure why I need to add images to the workbook - is this something that's expected of us. Sorry for all these questions but I'm new to this process.

gajackson1963 avatar Jul 30 '22 13:07 gajackson1963

@v-spadarthi Hello, when you say the workbook is empty, are you saying you're trying to analyse the data the workbook is designed for? The workbook has 2 charts and 2 graphs but data will only appear if you have Sentinel for SAP deployed and it's collecting data from the attached SAP systems. Please confirm. Also, not sure why I need to add images to the workbook - is this something that's expected of us. Sorry for all these questions but I'm new to this process.

gajackson1963 avatar Aug 08 '22 08:08 gajackson1963

Hi @gajackson1963 We are not able to see any graphs or charts. Just getting the blank page. image Can you please recheck and confirm. Thanks

v-mchatla avatar Sep 06 '22 11:09 v-mchatla

@gajackson1963 Can you please make the required changes? Thanks

NikTripathi avatar Sep 08 '22 19:09 NikTripathi

@gajackson1963: Can you please make the required changes. Thanks!!

v-spadarthi avatar Sep 15 '22 09:09 v-spadarthi

I will revert as soon as possible. But have you installed the SAP threat detection content onto your Sentinel and connected to an SAP system? The workbooks are dependent on this being deployed.

gajackson1963 avatar Sep 15 '22 10:09 gajackson1963

Hey @gajackson1963, the actual workbook content starts from line 34 and ends at line 626, can you please remove other code as we are expecting just the workbook content. Can you please add the images for workbook once it runs sucessfully, thanks. image image

v-sabiraj avatar Sep 15 '22 12:09 v-sabiraj

@gajackson1963 : Please do the modifications suggested by @v-sabiraj

v-spadarthi avatar Sep 20 '22 06:09 v-spadarthi

Updates made as requested

gajackson1963 avatar Sep 20 '22 07:09 gajackson1963

@gajackson1963 : Could you please fix the validation errors. Thanks!! image

v-spadarthi avatar Sep 22 '22 13:09 v-spadarthi

@gajackson1963: Could you please remove the content in workbook "workbookContent": after that i have deployed in our workspace looks like below image Please add some images and deploy into your workspace and let us know. For example, please refer below workbook and give images and charts if you have any https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/ARGOSCloudSecurity/Workbooks/ARGOSCloudSecurityWorkbook.json

v-spadarthi avatar Sep 27 '22 10:09 v-spadarthi

@gajackson1963 : Please follow the instructions suggested by me and do the changes accordingly.

v-spadarthi avatar Sep 29 '22 10:09 v-spadarthi

Hi @gajackson1963 Please refer the sample workbook shared by @v-spadarthi and make necessary changes. Thanks

v-mchatla avatar Oct 04 '22 20:10 v-mchatla

Hi @gajackson1963 , Please refer the sample workbook shared by @v-spadarthi in previous comments and make necessary changes. Thanks

v-amolpatil avatar Oct 07 '22 04:10 v-amolpatil

@gajackson1963 : Please follow the instructions suggested by me and do the changes accordingly.

v-spadarthi avatar Oct 11 '22 06:10 v-spadarthi

I will look at the changes this evening. I have been unavailable for the past month so am just catching up.

gajackson1963 avatar Oct 11 '22 06:10 gajackson1963

@gajackson1963 : Please have a look and provide an update. Thanks!

v-spadarthi avatar Oct 13 '22 14:10 v-spadarthi

@gajackson1963 : Please have a look and provide an update. Thanks!

v-spadarthi avatar Oct 17 '22 07:10 v-spadarthi

@gajackson1963 : Please fix the below validation error image

v-spadarthi avatar Oct 18 '22 07:10 v-spadarthi

Hi @gajackson1963 Can you please add the watchlists in .json format. You can refer the watchlist template available on https://github.com/Azure/Azure-Sentinel/blob/master/Watchlists/Templates/WatchlistTemplate.json

NikTripathi avatar Oct 19 '22 06:10 NikTripathi

@gajackson1963 : Please resolve the validation errors and suggested by @NikTripathi comments as well

v-spadarthi avatar Oct 20 '22 07:10 v-spadarthi

@gajackson1963 : we have some validation errors please fix them.

v-laanjana avatar Oct 25 '22 04:10 v-laanjana

Hi @gajackson1963 Watchlist are containing duplicate values. Can you please fix them. image image

NikTripathi avatar Oct 26 '22 06:10 NikTripathi

@gajackson1963 : Please fix the below validation error image

v-spadarthi avatar Oct 28 '22 04:10 v-spadarthi

Which line of code is it complaining about now?

gajackson1963 avatar Oct 28 '22 14:10 gajackson1963

@gajackson1963: Please remove the fallbackresourceID and keep the fromTemplateId. image like below image Please follow the below workbook template to build workbook For example : https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/42Crunch%20API%20Protection/Workbooks/42CrunchAPIProtectionWorkbook.json

Please add the workbook meta data for a workbook in below path https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V2/WorkbookMetadata/WorkbooksMetadata.json

v-spadarthi avatar Oct 31 '22 10:10 v-spadarthi

@gajackson1963 : Please address the above comments suggested by me and Nikhil as well.

v-spadarthi avatar Nov 02 '22 00:11 v-spadarthi