Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Salesforce-asim-authentication parser

Open rushriva opened this issue 3 years ago • 15 comments

Required items, please complete

Change(s):

  • Added asim authentication parser for Salesforce

Reason for Change(s):

  • Salesforce content enrichment

Version Updated:

  • NA

Testing Completed:

  • yes

Checked that the validations are passing and have addressed any issues that are present:

  • NA

Guidance <- remove section before submitting


rushriva avatar Sep 16 '22 11:09 rushriva

Hi @rushriva: to help me review -

  • Where are the sample logs located?
  • Did you run the ASIM testers? If so, can you share the restults?

oshezaf avatar Sep 16 '22 13:09 oshezaf

Hi @rushriva: to help me review -

  • Where are the sample logs located?
  • Did you run the ASIM testers? If so, can you share the restults?

@oshezaf - Please find response in-line

  1. Sample logs - I will mail you workspace with sample logs in separate mail
  2. ASIM tester output - attached in this comment. ASimtester-output-SalesforceSC.csv

rushriva avatar Sep 20 '22 14:09 rushriva

First, while there are many comments... You did a very good job. Don't let the many comments here deter you.

As to the comments:

  • You need to create the vim parser as well. Can be a second step after this one is finished.

  • Did you add sample data based on the workspace to either the public repository or the private one (Prateek can help with the datails)?

  • You probably did not run the data tester.

  • I noticed that you added the project statement after testing, which is good. Notice a missing field (see later).

  • I need to update testing. There are fields that need setting and are not flagged. Will do it ASAP. It might lead to additional notes.

  • Additional mappings

    • api_version_s -> EventProductVersion
    • organization_id_s -> TargetUserScope (this is a very new additional to the schema, needed for UEBA)
    • cipher_suite_s -> TlsCipher (not yet defined, but seems useful, will be added)
    • tls_protocol_s -> TlsVersion (not yet defined, but seems useful, will be added)
    • Do you know what login_key_s is?

@oshezaf - I will create vim parser once asim parser is approved with changes. I have executed data tester, following fields need to be added - EventProduct - Salesforce Service Cloud TargetUserIdType - SalesforceId image

rushriva avatar Sep 30 '22 10:09 rushriva

Hello @v-sabiraj please look into this

v-prasadboke avatar May 03 '23 05:05 v-prasadboke

Hello @v-sabiraj any updates on the above

v-prasadboke avatar May 05 '23 05:05 v-prasadboke

Hello @v-sabiraj waiting for your feedback

v-prasadboke avatar May 09 '23 12:05 v-prasadboke

Hello @oshezaf please look into the changes

v-prasadboke avatar May 18 '23 16:05 v-prasadboke

ASIM parsers have been changed. ARM templates were regenerated from the updated KQL function YAML files. To find the new ARM templates, pull your branch.

github-actions[bot] avatar Jun 28 '23 19:06 github-actions[bot]

@v-atulyadav can you please check the one validation which shows Queued?

vakohl avatar Sep 01 '23 07:09 vakohl

@microsoft-github-policy-service agree [company="Microsoft"]

vakohl avatar Dec 08 '23 10:12 vakohl

@rushriva please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.

@microsoft-github-policy-service agree [company="{your company}"]

Options:

  • (default - no company specified) I have sole ownership of intellectual property rights to my Submissions and I am not making Submissions in the course of work for my employer.
@microsoft-github-policy-service agree
  • (when company given) I am making Submissions in the course of work for my employer (or my employer has intellectual property rights in my Submissions by contract or applicable law). I have permission from my employer to make Submissions and enter into this Agreement on behalf of my employer. By signing below, the defined term “You” includes me and my employer.
@microsoft-github-policy-service agree company="Microsoft"

Contributor License Agreement

@microsoft-github-policy-service agree [company="Microsoft"]

vakohl avatar Dec 08 '23 10:12 vakohl

@rushriva please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.

@microsoft-github-policy-service agree [company="{your company}"]

Options:

  • (default - no company specified) I have sole ownership of intellectual property rights to my Submissions and I am not making Submissions in the course of work for my employer.
@microsoft-github-policy-service agree
  • (when company given) I am making Submissions in the course of work for my employer (or my employer has intellectual property rights in my Submissions by contract or applicable law). I have permission from my employer to make Submissions and enter into this Agreement on behalf of my employer. By signing below, the defined term “You” includes me and my employer.
@microsoft-github-policy-service agree company="Microsoft"

Contributor License Agreement

@microsoft-github-policy-service agree company="Microsoft"

vakohl avatar Dec 08 '23 10:12 vakohl

@rushriva please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.

@microsoft-github-policy-service agree [company="{your company}"]

Options:

  • (default - no company specified) I have sole ownership of intellectual property rights to my Submissions and I am not making Submissions in the course of work for my employer.
@microsoft-github-policy-service agree
  • (when company given) I am making Submissions in the course of work for my employer (or my employer has intellectual property rights in my Submissions by contract or applicable law). I have permission from my employer to make Submissions and enter into this Agreement on behalf of my employer. By signing below, the defined term “You” includes me and my employer.
@microsoft-github-policy-service agree company="Microsoft"

Contributor License Agreement

@microsoft-github-policy-service agree [company="Microsoft"]

@microsoft-github-policy-service agree

@microsoft-github-policy-service agree company="Microsoft"

vakohl avatar Dec 10 '23 06:12 vakohl

@anki-narravula can you please validate the comments?

vakohl avatar Jan 08 '24 11:01 vakohl

Hi @vakohl, This branch has conflicts. Could you please check and resolve it. Thanks!

v-sudkharat avatar Feb 19 '24 06:02 v-sudkharat

@microsoft-github-policy-service agree [company="Microsoft"]

v-sudkharat avatar Feb 21 '24 09:02 v-sudkharat