Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Updating NGFW by Palo Alto Networks with correct connector id #11509

Merged
merged 5 commits into from
Dec 2, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -235,7 +235,7 @@
"ValenceSecurity",
"HVPollingIDAzureFunctions",
"CBSPollingIDAzureFunctions",
"CloudNgfwByPAN",
"AzureCloudNGFWByPaloAltoNetworks",
"PaloAltoNetworksAma",
"FortinetAma",
"CrowdStrikeFalconEndpointProtectionAma",
Expand All @@ -257,4 +257,4 @@
"IllumioSaaSDataConnector",
"CTERA",
"Workday"
]
]
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ description: |
severity: Low
status: Available
requiredDataConnectors:
- connectorId: CloudNgfwByPAN
- connectorId: AzureCloudNGFWByPaloAltoNetworks
dataTypes:
- fluentbit_CL
queryFrequency: 1d
Expand Down Expand Up @@ -63,5 +63,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPAddress
version: 1.0.3
version: 1.0.4
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ description: |
severity: Low
status: Available
requiredDataConnectors:
- connectorId: CloudNgfwByPAN
- connectorId: AzureCloudNGFWByPaloAltoNetworks
dataTypes:
- fluentbit_CL
queryFrequency: 1h
Expand Down Expand Up @@ -50,5 +50,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPAddress
version: 1.0.4
version: 1.0.5
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: CloudNgfwByPAN
- connectorId: AzureCloudNGFWByPaloAltoNetworks
dataTypes:
- fluentbit_CL
queryFrequency: 1h
Expand Down Expand Up @@ -53,5 +53,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: src_ip
version: 1.0.0
version: 1.0.1
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
"Description": "The [Azure Cloud NGFW By Palo Alto Networks](https://docs.paloaltonetworks.com/cloud-ngfw/azure) Solution for Microsoft Sentinel allows you to easily connect your Cloud NGFW logs with Microsoft Sentinel, to view dashboards, create custom alerts, and improve investigation. This gives you more insight into your organization's network and improves your security operation capabilities. This solution also contains playbooks to help in automated remediation. \n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n\na. [Agent-based log collection (CEF over Syslog)](https://docs.microsoft.com/azure/sentinel/connect-common-event-format)",
"Data Connectors": [
"Data Connectors/Azure Cloud NGFW By Palo Alto Networks/CloudNgfwByPAN.json"
],
],
"Hunting Queries": [
"Solutions/Azure Cloud NGFW By Palo Alto Networks/Hunting Queries/CloudNGFW-HighRiskPorts.yaml",
"Solutions/Azure Cloud NGFW By Palo Alto Networks/Hunting Queries/CloudNGFW-PotentialBeaconing.yaml"
Expand All @@ -19,12 +19,10 @@
"Solutions/Azure Cloud NGFW By Palo Alto Networks/Analytic Rules/CloudNGFW-NetworkBeaconing.yaml",
"Solutions/Azure Cloud NGFW By Palo Alto Networks/Analytic Rules/CloudNGFW-PortScanning.yaml"
],
"Playbooks": [

],
"Playbooks": [],
"BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Azure Cloud NGFW by Palo Alto Networks\\",
"Version": "3.0.0",
"Version": "3.0.1",
"Metadata": "SolutionMetadata.json",
"TemplateSpec": true,
"Is1Pconnector": false
}
}
Binary file not shown.
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"config": {
"isWizard": false,
"basics": {
"description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/PaloAlto-PAN-OS/logo/Palo-alto-logo.png\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Azure%20Cloud%20NGFW%20by%20Palo%20Alto%20Networks/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe [Azure Cloud NGFW By Palo Alto Networks](https://docs.paloaltonetworks.com/cloud-ngfw/azure) Solution for Microsoft Sentinel allows you to easily connect your Cloud NGFW logs with Microsoft Sentinel, to view dashboards, create custom alerts, and improve investigation. This gives you more insight into your organization's network and improves your security operation capabilities. This solution also contains playbooks to help in automated remediation. \n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n\na. [Agent-based log collection (CEF over Syslog)](https://docs.microsoft.com/azure/sentinel/connect-common-event-format)\n\n**Data Connectors:** 1, **Workbooks:** 2, **Analytic Rules:** 3, **Hunting Queries:** 2\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)",
"description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/PaloAlto-PAN-OS/logo/Palo-alto-logo.png\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Azure%20Cloud%20NGFW%20By%20Palo%20Alto%20Networks/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe [Azure Cloud NGFW By Palo Alto Networks](https://docs.paloaltonetworks.com/cloud-ngfw/azure) Solution for Microsoft Sentinel allows you to easily connect your Cloud NGFW logs with Microsoft Sentinel, to view dashboards, create custom alerts, and improve investigation. This gives you more insight into your organization's network and improves your security operation capabilities. This solution also contains playbooks to help in automated remediation. \n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n\na. [Agent-based log collection (CEF over Syslog)](https://docs.microsoft.com/azure/sentinel/connect-common-event-format)\n\n**Data Connectors:** 1, **Workbooks:** 2, **Analytic Rules:** 3, **Hunting Queries:** 2\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)",
"subscription": {
"resourceProviders": [
"Microsoft.OperationsManagement/solutions",
Expand Down
Loading
Loading