From 6c6d57042ca74dd9a23e2ef4bbb281055f641226 Mon Sep 17 00:00:00 2001 From: v-prasadboke Date: Wed, 22 Jan 2025 17:24:52 +0530 Subject: [PATCH] Data Connector queries updated --- .../Data Connectors/CTERA_Data_Connector.json | 8 ++++---- Solutions/CTERA/Package/3.0.1.zip | Bin 12436 -> 12466 bytes Solutions/CTERA/Package/mainTemplate.json | 12 ++++++------ 3 files changed, 10 insertions(+), 10 deletions(-) diff --git a/Solutions/CTERA/Data Connectors/CTERA_Data_Connector.json b/Solutions/CTERA/Data Connectors/CTERA_Data_Connector.json index 1273c5e1c29..0db838fb930 100644 --- a/Solutions/CTERA/Data Connectors/CTERA_Data_Connector.json +++ b/Solutions/CTERA/Data Connectors/CTERA_Data_Connector.json @@ -37,16 +37,16 @@ { "type": "IsConnectedQuery", "value": [ - "Syslog\n | where TimeGenerated > ago(3d)\n |take 1\n | project IsConnected = true" + "Syslog\n | where TimeGenerated > ago(3d)\n | where Message contains \"gw-audit[-]:\" or Message contains \"portal portal[-]:\"\n | take 1\n | project IsConnected = true" ] } ], "dataTypes": [ { - "name": "Syslog", - "lastDataReceivedQuery": "Syslog\n | summarize Time = max(TimeGenerated)\n | where isnotempty(Time)" + "name": "Syslog (CTERA)", + "lastDataReceivedQuery": "Syslog\n | where Message contains \"gw-audit[-]:\" or Message contains \"portal portal[-]:\"\n | summarize Time = max(TimeGenerated)\n | where isnotempty(Time)" } - ], + ], "availability": { "status": 1, "isPreview": false diff --git a/Solutions/CTERA/Package/3.0.1.zip b/Solutions/CTERA/Package/3.0.1.zip index d9f60c550a0372146049a1067d8033ef3e56768b..408149e26afc5762bcb562db2417cfd905d17698 100644 GIT binary patch delta 9927 zcmV;&COFxYVX|QjP)h>@6aWAK2mtbmHn9!X2@dj#Hd?+kP9+c~001O^lko`{e_eZX z+sKjsKUMh-Q@p#Pv`13nQ6!U;PtWJy|BjHxfBMr)x-c5gNaHdHmj1JY1O7{A zVK~N|E~pc9jDM{>+L^iw@ytKye;syD+J}SoVfVnKOWVE0au;;5w2gpv{^`5Ue>7U` z1yk1v;Mw1(=Uc9W@9B09@qgm^f(C|Z1lWSl_yhc8tb$9|!=gW2yn261-qPU4^{#x< zCjM%lUQ=ftT*A|C^s`B4#>x)l$7;^V|h1{`!=J6_|AK?+gFH1r1E3NtTmuQjnF!^#Sw`UbxqM zPv=Y{T*4KW_)G28)EMMXHWq%i=@dUTTani6HRbc>fByc*V%}pc=WwRi zwo)wrBHu?GXed+t*Y2F0I);54SW_SRl6sW9v8JBuyR(3t!?>{=YGe2MG*~TjS(&)* zRkw|#*Xu$)rcYO<6=1u3a^}oIU9s_nz6qflAQrK&Y1pn%0_n$!iR^=c?1m*|fin}Iv35AZB-(-59SyrD zgQG$JXw>g@7P42{zUbAqtlnld)9>YERTiQrDjzHB2iKWd^E0!X!A0V!N=|vC(!-8~ z2M!D@*ZYA_6WO$LN~-VC6w|&_lAymqNfiBiVF}L6J!ur+e`7NoDV?8}AVHLjVV^;b z`DNfAgu~l!wuovR!Utd-T1268PNyr+3T{IZu~s1&g()5L%;aQCs7N$bFjMGz|`hEg|NZfGPW7ANmK*IZ3Q zl@jd@j4K*ze~3CPTEjzZd9&3tr%m>Oa0bpf1A>OOI;;9pZ40MTigErvUH3}n69STk zP%j%;V%SC0IP6-RW1x^jbdNiB{fB^0YFu<*_lDElzb*X3>Z< z&sr0irIe%>xu)rtGNvh`#oHJbHgQNCfU>fZc^LW@E9M5L`lfF5D?UO=D zC6qs$Qfho^Q!l`Ja)e+{H_NPpb~4xuFFDvsa-npsrc*XjW5Zipjl%^uwuMtE z#}j{Hf0HR3XE3o0PpfdRNQHalRhSh$G7gW1)SR`u(^;=QIP4#{C&tONJ?#$%=43QD zJTa+Og?pQ;aGCd)SK;1{RJa@$6;!yldlfFl(;6z=FH+%tYQ>^eVODh59}Q={69B2E zBN%J_o&gP=&f1f1@3?35C!^_Lq*dYm<|a(O*&#IaxZ9@vVb7!|hm%ovqE+F+<|N$3+Dd9_(I)OYyXZ3J;4^cvxPAS<&O;KD2JyZ}*RBw>=n{llJjs(ru5Xhr=E{ ze;S;eoaooW!_8H=%=^o$@Nh>eT#kzhDm>i13YX$(4HX_0sqm=03bUev+0p38m>F$z zG#a%B)Eu-YgJHjI3}!>a><_!gIaYYIxeAwge|Z%i?MQ{oaZy2qN4rB-H1*h=f`&j!5+Sy~EMTe_g>3*6kluau-E6IEbXO7uPu6`6cui6y)P|g9pe+R67A6V zkf|_XKt#ME1SwF*^nZ3Dv9RBFfA6f6dT30qAU-JRtyHx^iHZ0aaRyxk4GS#Q+n(jc z=WzlkY%-P7CO1}a8AbJ6^Ijw|cR8a4K6poVP5d?Y5c3qiC>{Hx)uYH+p=be@S1d~D zOZ;Ihav||7V`Ry{m^|W&zL{yP=(tuIkQ$WTHqP}KgEFkLfpv&`+%ssee>-qP0#}y9 zO!S|q0})fxzn*23(G3Mvfp`=DDncl-%Rxyi6~v)NWMnpx%g_pJB`oLs*0)_HdMDo8 z)x@@Z2p-A^&3he~np(=Req(r7rhCJLdI7OHoCbQqN!S@Ia3>=+$(_wW{$$}g7L_BzFm6M2q2^@;Ne+he`+j^iDg?TR7UC+#(;Q{v`w9{L(T$-dz;!TXdN-aAR%&X z`76V={)O~0ddOcb;LXIap#f62d;*^cDqjm;Y*Y4Ii#5ljjs>xC#uT*8S89ki8nzFC zdRz(NwPHg-JlIh9BEpVy;u8q*@!iFZ0fAc3PACtdjqDW$ZV{0ye+=VtpzRR0=V9d5 z1oZI=UT&@+jL(IZ`%7zTxvLm01Eh2fLlzr!YC;GW8!Ps0i$FBiCAF76BhB7t&293|ABXZ1+6roBUrp4XH>9Fud$Ua{wN_C_8Z7!VfoBtPcID&`)U#DfWD%* zK`yLyRCa1)j2Q(me`iY|M>`rlGeUOW(_dGX$7+6WfLbwqed{_@Q*-Va%S&7>T3NPI z{$-9kRv%0QjBpvRjeFD?sc^ps+_WcHg`ZJW+vrjLfyD^@e7!o=_?TidcwS3Y2~ z3yV;<_+K;?$Ef-SOk{KeDI}(E)7|dtb`0*M3^WpFK@5gWO z-~Dl;1>uIm3ci8YfC9pD=&vxu($sL^J^%3ce}DWYyPndZcah@9NVv-)0)pwN{=x`g zJ%XAwr@xW!e}Kpzt^Lk7T)3TY#tp0mW@`a6!N0)7y0967mrn7&d;4T^s}R$vP3sQ& z9;^Ya`+l>&2YnwmpdOdz!|Lj&9m+%rO~6r75A@>B&h1BOfLafsM-9SFDD1<~%+{T| zVdqA(RqNhub9_+?>*WQ^(5#Pr05q%_tWN6zT*X>Pe@g{eo3Isv6yzuT*4%>0uCS;R z`$x9q{{fcru(&hUTHML4_L(m>YSiRQQ2h$-S{(S$yo;5Qi#zx%1$bdCDBCjwsA7^A z#F)E#eRDrnMu;78p#Xp$A7(|l4E)gk_-x!DxQ9#^5_XIKhnEy|5kMtf@db7w2xAk4 zS?Hs{e*<=OynNieuMm>B05PxCKN7y-0wsHFE3u!q>oEKPH{S2X1|_kfxMOigBLKS_ zgu5_)+l%#lyu&TuaS`4wB+{*qGCbaU!WsBaG=>}1UaR#N(9OTeu6ECjPMNxgp zOr_0v@Uen^;n7YHyhXs-c|e!j*w>%afUK4(tR{xJ&rOexIsB|ctcn-9YswAvkZ?WZe@9QD5&k+tdxdxHGYO~ z@^`^xe6XEEA6ofVuz=AtO`p?TLotLdv{%bENUTjmNwvAkwFT*RPtg`^z<>1)Srg#D zxqzo4+57^U^;%(F?W62fM!b8_B9QJgk{Ea3KE#a|j=X#{chjvOOz$wlZKkcKf9T#M zZ@4#woB{+LkiFA4r~9bR%(%y_05*;x^;CLfZE+yJ^I*-mWH*D=-P>_Ik#Dhd1iX3N z`mQrhVaLfkj1!uI4MOJ)tVEHz9lj^(b^fl-eOsru#h2N?-stu>5oO|Q^qHGx#D&zl+Jz8R%00Z(?oT)TW92!<_;tnu$%456ud zbGnWYegtdm-Y~Xc`vlu$HuS9mbDwGGJLE?w0A6U23XBxhg12A?2R?YIe?Q=m2mdmx z7-4o_p|6##kikyo*xiqNa*1G5!*il+6>OzIo%YHi64>*|9P9yIAL0s5@A8w zSiNnBGRee2u_O%`-iXlIe;$AnRy<}honiyt5I=ifCG-bc&ElmPCyzcuNsP5HxHlED zRGh&jGsY^`MVTe9HwnQLG`P665m>S@GE!C(Y$CNYmf|M!O&RiuC+5i*#aZnR)2V$f zZcrG|rD<7a#v`5wsX~iHN~Lm5(gv<^AoHE!1sLK}&|Ym8r$hw^e?_`d14D0aZj`-j zV-3TpepL*wDi|2-ESUDsIVvQ}Xo5-8fz}_hYD+jZvnoE+)GO3QwT>9y=PYhEk=05$ za9f0H?1GuIc)@pOq2G!lbFA6uk93RVV z{xG?ZH6od6MM?!$XJ?~%7i$`4-G2d(D^t0(eDi%N<}QQ7OGFc93$;x2;3mP}m4XHH&Sz{CaslYS%Evp&~+I_vu~r-Y39Wxz)+z+Dp??j3+jl*17~)=P2mevaV;)e zA4Gs{e~YKW#MlN)h#Nk@`Uk~{=^jOnM@)c;HJ9M^W=mgO53#_eD5GS0&G2Q7qY8=G z+El+pHwJ4%>(Qfb143$IJOL8e z3qOm21K;3x99gXPFVu$d$QFqTG$otXA%yh}e<*|jb^^VMoFM=WZF&t@JYm5gT%0`4 zgRe+&Nfyy!>em^M9sd7cXcK}?M3PZ6MGN|xwdMTH_r!?s2(brLFWBZwL;Qu|5}k45 z3vi0!WXuJy1SDp>mh-sgF}$^)V05Ncd{Us<#%492}7MjD|?h%KbYwd`w3@s4Xh#kzmTTvG9|@lxh|vF;_;8D>`*Cu z*875gs_9|<1-7S4_DU(l{)4emJZo}%Ofv(qSJ6U*dYB*v<8-g0frv`5e=_y!!HpJd zOWtVd<7i2+gM;KF&TFu`m0RF5lU3`T47!GSJZRHnbJiZrVADM5kMLeYI+~i@!@;aK zV=WQea8^m~!(ooPTus=vJKT;QoGzDuw6gcM<<_(^@KG%bwMr z29({q`SJY3=Kj0SlJuYH?ejPY^#|P9x#%Lrg^73wE-ts@U(f$Q6iUw@Bt`&Dl*b2N zvSX4I9#Q`}7;BiqI{ePB4)$0@ob&7)w=Tercn9A_h##|`LH+{H## z-t9%HL&Ip$ww7rxf7Xngv=uo=mo-hEzv_+^uhU+={>UeRww+ZgIcocbI*WcP&FO0J|G4ynC78 z_b27dEml1_ydH{^x5TaGCB44cyl3CUo@8G;?0flpPC5C$e|>*(7yjj{8^@R8zP|-P zEBv-T#EYWa`~aTfyB$7I5aPxP5NbUx-+W0F=YV(*q}yyzZrwml+XKy22BzZ2bibAU)0 zG#ZMf1zhpV?ON*VG>Df^!O-&aMvb3f;Aa9pe}64@Va(^?e`O{t%*zNBY|559Wnq%($`9NH%<^Eb^zRByvOFNfzm$9jyAoKu z;%6|@9`uQxEi8aq9R{ zJstOR(fg%Jms$w1Vm9o8C&u(DKIaWH=R8)yf1|KWbbhd1pPFZagQAzPr~qjD8yZ}? zOdn5e`xOolTy2)O9e}q{^twf_UGFUE*Xw8sx1+d2(R-VUw|20t*`^mt_(kHIpKCq zv+LDIWsh=pNI6fQ5sDKY^XI zVvIDj!gSKk2#f%#LS|j>genc7DVc)Oyiv8wLX7;{W$|QP77;959*+OX_1WReJHq3U ze2vK87b2fGad)-@(dWIQhUsgV{wsm$lbbczsN6YB-`fzT&uH_;FnzU++ugwQeGS-0Yb*zLWdeve3sx-G?BcBRv-!Fje`!#I871;ib z;rn6Ij;|ZBPpX`#sA}4iMeO@pL!M-RQ^X!8AQN6-J_OvJrvVde6AyKqW77PTG}}!3 zh-^EsmGA&XHWn-iggXoKJE%8nf6T*76#(Q%xxym+xeR*G>)^Olvgz=N4__yTe3_V8C6F-(|(>W$9j3fB?OPQ*#VSw1FmoH1c_(I9xqU2hM%jLT;fAvZg*=TR1 zYVy=H%?g(s$pkK}5iK%YD8zZi7i4&Nc&Kp`urcr>9vYy|^j5@fzR?$j_F6muQ(Nu< z9F_HP?FZYH zAFQmsSlbV_1}M0O4@}2KNTOfe2UeBl7VP6w@qrBrd|-px2evgISOiJ_0ASgie&xQf zr0R)^s>VH8U)Vrvf6SBYf33bSu|-bZI8y8YBXbvq66Q9B5DpNKNoSS=#e)!muI3?A z?${<`;NGRLOu5`e?=8bZs=w@xJZ2mE%t(}?eGRACow&`m;5ggJb+)PV?5^Esk@iJh z2iO+u_kVbOYMRu9oj!gRIrzml5jzEiMVaRG(!Fu;sZRqxe_bqA{S_ZorYLS2Q@bge zvVpHI;-vQ0)!w>?l{oF4XI+C`o6}c57y~{BZ_{;mI6AIfcltil371K)cHONjtJ-xZ zvKf;zoYyhpebJyKqL)TqKn>TjdRYPy?#&uT`JriVW*In(p zt6g`ya^01+e;3-OIzwN6x2mF>y;?}l27o@8G;;%ooiJ^Al6A;k45w+#2vCjPqmklVcq8+ThtuuG7w-EFnIt#-HV%H3AhUTnkNRs~#K!_lT=B_uJd z?r5t@e{%~q@~Jr5Mg@+xQSE5kilgn!nXzmg2rAZBJ!NU0&}&uUo~*NNq_yWs_P?5| zo@OvGd;tCVFyW5oYs*{t_^SkQG#TL$brfz-QPt| zGw?33_lFWdfh4YYLfSc(HDL{p6y0@%M8a7;e|1$+c02G=3-IF*ytF7Uqh$IDs+s35 zh`5KURMU{R)LF6%=yKK$JXA(3A4oB;(wJQ4!jOS!(6-eLdI`d;eWm+mwD9yc`j3h^mBha9s$Sc-qxLc%?1+2k21 zfA;yFa_Ox(ZRh6Fi)e6Wk@GUZ0YA^rvK!TQ%6G z+&OGN+7PzSX!FLfeYI`d-N5!Gx6OiV4cphSeGS|13brq6FV=?bE3Spsfa`TEgd|4Q z;rgmHw_qC|CtQCC5vQKoV8Jg0^SQu50!#k+?f!<;2JTcb)n_{1dfsk;+oon9Do zr2b9$LnA!#JkADLc~G-g#h^cPmxI`Q=`N%aLukMx41Ue*OkUG4oyf6+3f zmmSSt9if%hN1dH?nTxIsdqu;Plx#ePsVEtMCGTDS!ggyf{8{_W z(MgA5p=mA$%08`;{3%i9>x~Rm7D~4Xgh|fxXXakB!t@P93fCu})StsWR(F5vWs4J8S9-h!%`S9K59hH= zr0vP^rOXkm#FN49dIi{>daeE1I07tNmJlrF|Lnx~8jTMuiVWF#A1z7Bf3Hp==|R_N z7K!`NsX41eIV_Fo6>QuROPnoYcd>jnUomo*)HhL4RkN=Zx$8YHy*@;eS)bD|#em(8(qIc)0UvFoq zUmn*RqkcKW?+f)SxndP$e{0mQM*V8kZ&#>aS#z-s)UU+;=W&64Il_C?px@ejJz3DN zUjX{4_xRSJ--ZEu>Fa2}V)!qqdC^VJUp@TSe=P8y64Aspx(5FWF{>KD`Mt31pI!E%?3-Vbn?eIaQL96oU1u&>>r^zR%v?C%UXf6U{0W8g4{_?g}_8Yc4he4omKw9v5twBf3Wo8?MdQE?`3$zqTG~xOQBh76?;h zkcO`0RC_MEXwBiBHN;{CmaB|F+LD&z3{&gTSNo0N^|5vI8kn|9~-h z@Sd{9A_snFVU8Ow#4m*X^zDK1BG#e{w*6fgx4=h6Q;aJ>e-L4rCtfWZ?O!>t;|0qG z+Z1>O`$qUzd;{*~Fr^?92FeQ}L}WuDZZj>;MOuoTu$h=EkDJp_W>Cbv@yV^bLIO}4 zHvhz6DFY4r7Q${s%n8f;m)tb^tfa^i2-U+uNTh^2-Ng;8kKsjAmIRVh zSb{*IJhbJOe;5I5A3@FMWChVZev23r2lG1F>^mz?e?#|?b*&zOBN3Nc*)!Bub^r+b zHLSKBvOsAW6L%G4w4e3CzezcgVV|1rG>d$wVKLp2L*=Cr7!a%EI3O$6^OaEpaEmPT z3s{wj>t1Od%S00_<&Iir6qQMw{#6R~AEgNM));wae^Q$?Bb@(|1(VCEbZ(6DRiOYg zmDXZTd~d3V#WQX?+-{-53qpDmCal+MckT+y^$9?SB_G``?{nZjPsOG;?_a;&KyD9X#fohQ`2rCMf^6#DD1%UY_p2B=^rMk9m zZf-gur2}1q`56QXHaiWMG;kSXfW=~=`fpz*yy?mq~obr-}ZZ-(Fg{qQ?vy5dFC zTfD1dhfG&Y_`k)BXH}Wb2j%ZBjlec?1MHsXYC+W7h>YGn&(-`t+i>b6cvioD)GSG7 zf0pM5?>I^Y>qRPnIzZ`;+P&lW9z`O4$u($VZBJeYrqUEOLAyMKm$m*iU5qEoI3d(H zhXo`ci!t_8enN0FBM5P`^ex3FaoNi`iw)RVFINFS5&HYz!T@6aWAK2mmKvHL(rW2@WS;HCpx6WQ_79006pulko`{e|_t6 z8#%J({}XZE0m0o3%Dp7TyChHB)9SW+S~0fU$I?vyFg>0k3#96(SjDa?O0DrYVxMIn zZJ%T_aj8OGP#2OCCAl;cZixgE$V4Ime3?jm`Op6#r13xf*(F^Xjpw9s83Zf;`Qah| zq_Z>}V?meH2|C8V)*kK5+@<)=e?RPZdnfJgu-)w)nsjBmw^;6iE?2e@(9VDRuJb<{ zE!M!ybprVA@6_`x*THsroi6@Qe7~fDVHyGU;0t~L9~tZ5()Ff+h!Z8f3|<5?OzPfoVif#pB+Meqr`IjfEp%JCBY>n|75~m88h0J z-TWuHxwK}N#PW$rJ?k2poO|w)6@PO|!U{~f`16(j!UYXXq)C>OZ&Hwz#q|;N4;nmZ zexM7c5ia2hOMIy$a%@1qK*1<#1!@fPCp!xt+jNG%HCvI^95m(kf6ZslJ{9vGV>yR2 zy|$HN`8U}faiF72_20M)a_SiNZD7rO7)$C=^46MpuJ6tRat`yxa;S~N>(gMp%4KEh zx>vn6lHP0x`J6son^u7R^2wRA0CmOA7tX7aQ$(_j>M6UN;z=hZOiIyRx{l$C#$j$eWUWRwtjM*xwSYmdl_6LzE#O7U#awP zAmIxKCYI~{#FvR|+BqfFb~MGbZAudK4=9PE{~#>EnRy_Me**m43};H`*A++*C1coU zP-Af!_=n;2_M0uD8i();unsMvP&ucwwPyvlA&FS8kc`5Vj(KKsvL#d`nmn1vHT--< zXQ;0|)re}iYc&sZm}|C*YPZc@$&L}n=^>1D2I`mKy<%INVfrp3*4<7pvvEj=T$e*~7A3`s>#jEf=mK_AvO{dM}^ zFlBnNjg0zza<251Ey`!Lppcjll{qqpN8|CdO-I9{_Hbw#?Gy8O)E*ws=Yx}hIfdhs zLP;f*Kb=x)d}>oKzSOY=)PdY$dr+hE_8uTdA?(ZLG%Oh8z3B zsg&c1e>d1<3db2tY{Szk+%Hn$et8vUMURZ`(TJM!c5gQCw};)qaeHc<%-XZTXlPEy z!|sVmwJO}-UWLoFUtWd#ds5+YTvSlu{{B_C6i*wd@SsSA2dN#4R)ty7(O^89_fG(% znvG$u4f+OjbT)5Kd;R0SF_?~L!?9L{2ivP~f0_2ntMFh?DqN0>3MxFyG;L ze`t7ea-!c0kG5CgGVPaF;nAK{xEvQ1RCu(16)wfo1}Z!*QsHrV6=p?;^P};RF*n-g zcsy^t%Z*fkH_o zv==zw^7oYflwqNyc>6`-?UxrXE7~8=kIdr}*hU^rVMBQ|o3;(J*K7BWd-L&l);pRF z%#z~m?@PQTSSTspL6LX|<;Ba2j!%X&SP*FYWPChr4`)WVZP5O(JsM1BbMyFUe>(3P zCB-|~lX%OpkSX5K5+%*w2G-BFH@1Ed#wMB1~qQcFs_obz*V|*c2q8%C^ zGZiKbh=^B&AO-4}{;y6X7WVo6f1Q<54~^Ls#0Mq4m8v!DVW&9!1UyMGLsRVo^$8 z<6p)i7ZTrP%q;m6lSf?9w=<0u9oI?+Qj@aR#FtbZ?kYFCaFD(?Bmc2?v7(?qtL!x$`;5pDbO+f>N+< z5yOGNw@Z&20fck~JUolce~gtewQLK8%1GV991smj+tisjx-gdOL^ClKP}yUQB`0=1x@P#!`XSrY~x5s@nlf8%nX?+~`QUM>}898m5>bk4CJx2d}gv|mj;G?wFq@UUs2p3 z7uGu}2Q@Ori~^Xme-)6U9gUtDAv+)F?`z9rHGecft(d;Pa~-Owx$unDCGHljEL$mm zGUpwu52gWTxQy<)a08GRmj!fsMloD6yJc3}rVCi8)y%0dHGInUwk*_@PuT3j zBGfJZ6D`Fts=fgW8Qnq(iRGL15EXF_hLBAlp(Vj5^=ief15%#~Rb1cU1 z#S7A0+_VjhC2V35wmCA%1t^sh@FMt`2a0ttX&g)@lg2d$^BFe&`W*lH_z(Q|(|7pq zvq_@`;fBHrzJ+E$0bx7zH<)5+YB=#;eEi41KYf>7PwCM6NbzGN+*J_)!E{uAX#}tz zLCspwKgbV2f8@{Bv(9&1xSj7N4Xg!bYY8jCzre)0a2SF{XZYWPXJmS-5Ywqm>kh^q ztO2dZe!H;;eV;U-9+&3B8tSMY%0dZUz*$mH^y0zJ9Y<+^S`T4F4Z=+*oWsz})`Pp{ z;6|%e>)vg1d{Ybia&XG^{!7PU{I=#ac&Oe+Af^upNRF;7pWmfiwdT8rHS?X?v+6cyIv%*+`NSXvsTivx2ta z2Y598e;|$!i7menTBJ)TIADHh{BaPIp%k5vujM-~0%*Z4EB0&$T4r1umd#Jy*g*~N z4L>k~wI93ClPF>N?*-WNoXp{{OtZ>mTfjziw$y+rF-+{eK!Wo0Q#*znxsmlt!%zCL zj(7i+NL)Tr+3we^oju2+9L$7!{sd*`LAMP`y?U7iH()d zX1IjCam*0_d2KFe`)3RAAF=vGxOk2kQTm7R+Eh{C zeL=EPy;2VX@C{>!i1$^jwL|8O6QR9E z=#MHy2wunv;{lxzxrL)1^90+cBn`;zkp^#RajU1RrW3;K0IgD$w1sLsr|$E*N$j)C4(IyY@`f498z zV9mH>H-pvv+i|?yZn2yFynEdGZZc2d@Wuy>6PkeyLO%%XM3K53wiAsyZ>w|P*6E#b zZ7t9P9x{FE%{Jlq%tqMj;Z#&%i)~&>9vfB@VAx$ zuuJ4R8~G0t%ebS6AFDQ_4m6>Vf0)eoEDLbwMS|F94`W-iE3{cnAQc<)X2!g4Mj1fB zDI72_DL)5-VGDy){CgKeXsX_xZX$%A!5X_aj4e1m!7-UleXGFSXBzqr`56j;Ll>k1 zGex!FEjYn}J6q}x__o1S3p++w-Ph>0WIJTAlR0+x(}CO~*wpZxDDeZ^e<@I>z4i}T z3=99aEga{E09S!~G5%qjec0v>*FOiw)PKRh=jV}Uk9UjEe@=2_7%kJv9uE%nRUnb{ zhpBRj50VQ1WtV|1VTP0v5jNVew_QgC$s9bfdl{WM7Iq6vjqrdX||yh^G{)&?AwZs9cw{F<>0Xd~bLGM#~iR zSDO$iQ30ZQuGARIo0}WuEZf+?aH@YQhF28~Om-HR`qvy4l4Ue;f0^l+!HD9yV7p(Dl z>sIwOJ+?q(ui>TEf9~>YcC1Cs8lB5y?wVYBEiS(Xe=W3j`??`e;by>H+z8m*2IbrU z(A%fNi2pJX`_&@#>j?ciLjNu!^b6wa)9}Ye@${wR=u5=U#}68b$)XSb(ch}l1^etN z$S04#k|ASy(5g5@EH5mAT{3RFO1yS)oOV%sc9CP}Q_gr7hmRE+nY)a$E)kfQEz~lB zc-zELSBksKf4l0iRlM}0h?CYwAeE9!<#^~jiG$t&6P4qgpGKT>rOP2Dj9WT5Y3sP< z%KNJOich{L^S43#@$T(k^*H0Zk1yVG)>n=r-dFtamV8!<6W(`x@Rq!mjsxCv{O^`* zmW=bQ<9oM>@4fe>aToErc}LWWY0^q1m8#-Ie~<|+f3>e{)wwKpnaeVKLyd&LJf(D& z>1Vh0lgTnY#nO+^<%PPJeV^?vl12KL5T2Ih+|G)DIfkLjD4P97s!lU6E&+xL^-;-9 zNL)}yG#lbaSaSvbX}0yn z{Sb>0e~R)PruPhAH;DRAgsG;+C3?qJ8>NoEZyOL&6J7L34Y3{{$c{oOtT`Gvw{DFE3w zlSv@L0wx|~BPh-W7?tEX_`(lhWV7=FPI!jENjyv7L}m({gxLZoVa7oA+cW$pD{r9M ze`Hn)!AT;CU^bZ)Cz@=6lUSCbJX)ySC4B0Wlvf=-A)sIhU+qNo)?$&vL-K*q5J^M1 zf5(Pj(@_sFq{}7633OMyG zPT&6Mq~B#fU!@*m$Paweg}>!$BtDunf1;~*AzxrN(wjNfvdl2cim~cA!y(wplRdNP zxj10*uKAbl&5y1Jn?U%Rxkn_^VqN0JV2-Yr&RZNrMm8ZZ#FyA`pwy5po6dt=0+F<0 zb^GB5zp_`*|dD1mC(U0f=d`mh0uYf3REuXcRBotaQsw+_xOSO{ZMK#4r zbPKEmH#eBo8O`*AGZ0Xe3Ima;f9U-zMVH*%wRXq!2Z6l+&MH1z6&RrZndv%P7jW+7 z6pt+;cQ-e1WC3AVt`fw;&nr`m$0tItp$q$OurNz{5E6ZsIWc6CY_7QR1+V1H;G>Wr z^b!IhS&@R76R(!Hu;RF6>eqvtE!da5*)qV{l3)iX$tPUbV0SBzz-K0_f7U-4_6+lQ z*rvzkygi)5p?NwO<7<0#JTrUU;k-X*JrT!nR!N@2VU4<6Pua0MJdPfou2z7wvUc0@ zXxf%XF#m9ByHoII`Y?IKSv@?rvQs&96^1qw*;Vi9z#PuGdYisHlkwWP?py?Yrwf-yx|KW=y{a1SXA`U|R2~Tz|x=3+j zBEAF{m)r5L7k?rOr56tpBY-Z-Nc>mq#vz5TsQ&_tH7sEr{u0&4PrO)ku_wQ*P>Qo9 zzHB39lTl90vlr}5w?7ePD7grQ7as)a1ClM|040P``9R@c>zckde}c=zfUwDpUEo^H zzx~=#hcq)tNWIXgQ>v=T14;s43UVd6sFE_E5HS?h>udpawtx)hQkJTi%JkO8vvG^W z?tnH<-@VeLFTkfy5CGK24d}DQ#b#DvreF2`EgH0)C9R8fBPRny&Mja~S9X;OC+4bC z9BFk%hpo(WGMPh`e|6p*ATQ4BAggbZ)S-0U3aiTF^vkB7HU?%od2jpn>bD1X;;;P> zzLt_;w|lxUf*oqv)>0#vag-? z{roehTzubsxVQ`da@B+5EAa~55}+0Sh8*HW(HnCBPw~?Zf1fA_abpE?dIq7R5Qm-p zNLzBnNmRzEM#Nmptj?oSQBK?ol2JtaY?uyrOm>1{M~>w$C9nMcp+NdLG%mu{)t9`u zyYM;lAKv_L%{yYeHU=m2;AoXV6htnGwDCV?KCQF&F(PO0pC5eewof{r@~bgPs}*r{ zOLblhkGO^&e-SVsHtXX*h_2lnAW{a6hGJ;}SNzGfmfD;K@$xAcT7KWC@e54+>_Y1m zOg-icdnK<;;Dv^Z-Y-SvUl;3Kc(18(Dgz*MuiV5o*xImUT}*U|$48)4ZpgbXduEh; zL_IN-jP=VR+6WNQnQ6P)I9r183L0gp!QAAJYHJBzfAogOI(jcPJ=LWNicR59Fpr6;a&8k)n-_(si7YI9oqBhT%S0GyfT6-4N z+4~BDf_P?}&UYjy=*l*8gk?7Qi|4LUI@0s6#V(A+0{pMcgoP;%p@L1>cBd>%GF$tB zyM$F9f9#dMt)NZ(+DWE8~ zG)7{xLtsh!@+G!def`=g%e=&?<5%@`+%LrFmnvOqBgBf?a0;Fpv#a=;H_BY|SOt&5 zHqrUXc71A|2@Z-HVNn6l_qQ~-beTS$+V*Rle;~NqEN?piZ=>jSi<;f+F6p=HXbO*` zctX*8n~INiaID#-7fSd=;)ms4C1*ydK38;dYPVU)E8H2eVGGCNjhP&*`NemdErEXb1GKh?RNs(zcqY6Oxp2nBlby^6BSiWd$NfAKx@d8>~D+M;{s$t z1Li}(?Rgq7!8Y+w$2lg=Z%MPmw2#QP14juDP-J7tl0dlgFu#NPvc@9JQ~^MKlq)R4 zpUa^4ybjJwC7TXk_^>%SC3lY8f9rGUgxEX}RL@TF)rjZzVtKtngqUaiD2kg;k&GoF z$*G*3wM$LOQ~A;WOR{2Hn9HR)Gap7k_lW`Ct75*REYD6FUhFef9-1A1Z)oc zjF$$eGrJYBn{V|+p}!Unz|@v|0GA~K&sr>~_p5RR`!6i;)4RAdvIQZkTwFpcm#&TE zQEc^9jE8>}WAteK8gd#}aBF<4S1~qm0o|djuq#j0{S$3!*uF6OE8EQ?S9pd|$lqI4 zu6kq_4(CSUJZZ2!0+R{*f8|~sRX^g*1OihB7AGPS}VLOe7SP!hy1|i%{MPg6~2h!(A8tBYp=q79|BHP?FZYJAFQms*w_!Y0VueE4@}2KNMcak2UeBl4(#Jo@qrBs zd|<=c2evaGSOiJ_1Yp^Me&fEdr0R)^s>VH8U)WG<%#-YYtG+OCL{7apQtSXD3m2vm z<~D{94iJz@=avJ-e}fQ#uI3?A-q0+_!ulcMpMRC)Z*-g=vEqrwmC$+b(_SQYD#A)w6f9o3T+Je6J!5Hv0c$cob z?)bQN-RZ|nCtN1I+I6?7tZLVtluPZpt6g`s>n?69>P&Nw{t8rK=&RuuIEnRmR zecsx2R}HD~a|f34 zsW|aQ1x~zCf9=HEnG=r(B=UH~Z`*&D)H+d7RkkPVzZ+>SdXjzZjIaH7_vF9Rgb>%a z+%nut+xYA1OK$gm$t~fdgFhXv=IBb}8Tq5XPiJ=Y2fq&|{$><&U2SOxTT5}jg(IK7 zA=j&K$Zc{%4#igAklU%x?G>F<$EUBa4S(0}w$Zp>f4kenPwj52Z^{WxsBg+CKlM$y z`lg&%FzSb$;HQ4rsnFe)1XuuExN~>gXiIlnMxVEKw^ajM?#A6#66_LWYj<1iZmZpG z`*OFHwHLc^w^acbH*mD+SP4mtsyo`M(%gZKd@7E%ae)s%ywwf9fvT1q?as2VN>8mJg(uS82kYmCB*^ zcQ(FBQhe0QkjZ(8NqK=OCeG-MCdo>RccXrNNle4~^`%_jOTRmKw7!@6^`-kvzsC&? zHX(k?&LPLF50>J;>>%Nuv~2Q@6#M<2a_McjZ0F|Ei)e!IQcZe^ab+qN1v3dxhzNXL<;vOpVg1UGgj}}?m?>f&aYRDQSE{2iZE9t;`uO_I{H;mu8nt{f^3a))hJhu za@`NgwYj-SqFg#_vF#Zq8|4x!e^g*x(F2{ZTB9zk8L)0OFMo%BZ~A}!xHi^$*P;+*Pa#|X*D>%3%wm3V)?qd0Df4*VlE~#&# zqN--!DstCO z{jw9C)TrMBNB#QR(?$QzQNRA)P`^B`w?_SPh~F3LS8~TH$kwP|jr!H7-@Z`4vgTqJ zs9%Zm&*K99a)kG&LBEape|oZ@-=F~WQ{VBeLBA~n_R`PMe#7uzQuCshp1*ncZ}3>) zKP94xYjh3%6=GI3`1hE>zx#ibwT=#4MOJ1e-dA~;5rX9&8NDCiF#AE$8aRC5z~Ml9 zLK)mSa5&f-aG1yS*1%y7@%sV}OYU_A*%~;kfx{X&+!t_I)?91{e;k%PIXy1eFh_Kc z8aCXRuYJIVGJb6{)NtdtJ}nTY$RG_}$))yO4AF+uJ8O!?3ar*s+w$Q+_o}F*vQPRY zShD0r->+VN?+2diEMC5YliTy}55-^Py-f|D5)WbpJj@k{Cy}{p+wKkSs-|@A!U@uH z;QVRZ_z8Y5wGqgye_l=;ApZaU&;KPK*g(Vzknat038Y_4Lga1%h~Rq4fVxwJ?D)U! zbIh~lQ2Q|OC_M!D4uc^N zJ94VLG6Dl)l^h3T<$As{YXEMMg?sPKZ2-h>J3^~PPe!g77a z-#h;GV$uMYhza1}q;WJ_{Q-YoQd|$izh9Qy^X2R)b@`ies$`$ma#yxw^l#!jdBiU0 zL{vw`lN!c4xOBZ#e_{=icQjxNdZJ}mXDvI`Ec-O4MSs1*466A}>RJ+&f0)6j8>kkE zg0Q1te<}ao8(sjIU*cO>53W?#*3HdLC!}oC8AK*46G;gSY!V+^oZEL8v9tE86; zkRq@%MwyUusRC#TLqnK>-RKq7RBQeeUQo$)@MzG87!7$(F+Q3}0p+tJZFVJ2ZbYRG znUK|Y(f@*EXH^m?^|T3;vTlNwPZZS4P88I8e-KRfwM_T7V!EHrbpJsxJ6 zdKZz=`{%iu|7RCYodnP7pPw{a(z)gN!F!HU!G4hnpbk*Fqjvu|enydqUvdwc*xQpg zOo6F%MNQByZ{cO_e@z$T$ue#THO^rJ3CLoMJ(Zsj+{_3<+%A1f@l9OTIA^f|2kX^3 z;5S15^FQGK{~u6G0Rj{N6aWAK2mmKvHIpYWLJlWiHCpx6WQ_79006pulXoyR2Kp}m G00028yIs2g diff --git a/Solutions/CTERA/Package/mainTemplate.json b/Solutions/CTERA/Package/mainTemplate.json index 01ba49d7570..cef1c105631 100644 --- a/Solutions/CTERA/Package/mainTemplate.json +++ b/Solutions/CTERA/Package/mainTemplate.json @@ -182,14 +182,14 @@ { "type": "IsConnectedQuery", "value": [ - "Syslog\n | where TimeGenerated > ago(3d)\n |take 1\n | project IsConnected = true" + "Syslog\n | where TimeGenerated > ago(3d)\n | where Message contains \"gw-audit[-]:\" or Message contains \"portal portal[-]:\"\n | take 1\n | project IsConnected = true" ] } ], "dataTypes": [ { - "name": "Syslog", - "lastDataReceivedQuery": "Syslog\n | summarize Time = max(TimeGenerated)\n | where isnotempty(Time)" + "name": "Syslog (CTERA)", + "lastDataReceivedQuery": "Syslog\n | where Message contains \"gw-audit[-]:\" or Message contains \"portal portal[-]:\"\n | summarize Time = max(TimeGenerated)\n | where isnotempty(Time)" } ], "availability": { @@ -364,15 +364,15 @@ ], "dataTypes": [ { - "name": "Syslog", - "lastDataReceivedQuery": "Syslog\n | summarize Time = max(TimeGenerated)\n | where isnotempty(Time)" + "name": "Syslog (CTERA)", + "lastDataReceivedQuery": "Syslog\n | where Message contains \"gw-audit[-]:\" or Message contains \"portal portal[-]:\"\n | summarize Time = max(TimeGenerated)\n | where isnotempty(Time)" } ], "connectivityCriterias": [ { "type": "IsConnectedQuery", "value": [ - "Syslog\n | where TimeGenerated > ago(3d)\n |take 1\n | project IsConnected = true" + "Syslog\n | where TimeGenerated > ago(3d)\n | where Message contains \"gw-audit[-]:\" or Message contains \"portal portal[-]:\"\n | take 1\n | project IsConnected = true" ] } ],