Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

authentication native parser #11545

Open
wants to merge 110 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
110 commits
Select commit Hold shift + click to select a range
834a40f
authentication native parser
Alekhya0824 Dec 10, 2024
c3d2bfe
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Dec 10, 2024
1c0acea
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 10, 2024
26de32a
updated
Alekhya0824 Dec 10, 2024
7d2414b
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 10, 2024
a20a6da
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Dec 10, 2024
d0c4414
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 10, 2024
fce99af
updated
Alekhya0824 Dec 10, 2024
087ce12
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 10, 2024
623e0d4
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 10, 2024
edfdcf9
updated
Alekhya0824 Dec 10, 2024
a8c06c8
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 10, 2024
0b71f42
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 10, 2024
009d9cc
updated
Alekhya0824 Dec 10, 2024
e953b01
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 10, 2024
73ce78f
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Dec 10, 2024
3f0c527
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 10, 2024
2d15ede
updated
Alekhya0824 Dec 10, 2024
8a3fed8
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 10, 2024
9abc514
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 10, 2024
fe3b467
updated
Alekhya0824 Dec 10, 2024
7910cd0
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 10, 2024
d11b196
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 10, 2024
87c378b
UPDATED
Alekhya0824 Dec 11, 2024
e525f9c
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 11, 2024
c2a960f
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 11, 2024
05fbb73
updated
Alekhya0824 Dec 11, 2024
452bd4d
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 11, 2024
1526d01
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 11, 2024
d25c7cd
updated
Alekhya0824 Dec 11, 2024
33547e3
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 11, 2024
ca38598
updated
Alekhya0824 Dec 11, 2024
d4953c3
UPDATED
Alekhya0824 Dec 11, 2024
c2b9b4f
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Dec 11, 2024
a1dd8fc
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 11, 2024
c5effb7
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Alekhya0824 Dec 12, 2024
27b19cc
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 12, 2024
b54ffeb
updated
Alekhya0824 Dec 12, 2024
5f842ee
updated
Alekhya0824 Dec 12, 2024
6dfdd1c
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 12, 2024
d4145b1
updated
Alekhya0824 Dec 12, 2024
4c3869b
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 12, 2024
6d920f7
updated
Alekhya0824 Dec 12, 2024
ad45815
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 12, 2024
fa318b8
updated
Alekhya0824 Dec 19, 2024
3bd169c
updated
Alekhya0824 Dec 19, 2024
195adcb
updated
Alekhya0824 Dec 19, 2024
f66282e
updated
Alekhya0824 Dec 19, 2024
7e7b4c6
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Dec 19, 2024
8a9780e
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 19, 2024
6007d10
updated
Alekhya0824 Dec 20, 2024
8407042
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 20, 2024
b4e5e3d
update
Alekhya0824 Dec 20, 2024
7eabb40
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 20, 2024
d20770f
updated
Alekhya0824 Dec 20, 2024
9e7bdbe
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 20, 2024
0a79db6
updated
Alekhya0824 Dec 20, 2024
1802454
UPDATED
Alekhya0824 Dec 20, 2024
2f361c8
update
Alekhya0824 Dec 24, 2024
41306cb
update
Alekhya0824 Dec 24, 2024
9277f18
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Dec 24, 2024
5403de9
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 24, 2024
78ba248
update
Alekhya0824 Dec 30, 2024
849388b
update
Alekhya0824 Dec 30, 2024
e258327
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Dec 30, 2024
7d4e7fe
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 30, 2024
9109a6a
update
Alekhya0824 Dec 30, 2024
a0a2e87
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Dec 30, 2024
771015b
update
Alekhya0824 Dec 30, 2024
b8cf97f
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Dec 30, 2024
5816e1b
updated
Alekhya0824 Jan 2, 2025
81e2283
updated
Alekhya0824 Jan 2, 2025
8b5a0e9
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Jan 2, 2025
829ff57
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 2, 2025
234bc00
update
Alekhya0824 Jan 2, 2025
dd37bdb
update
Alekhya0824 Jan 2, 2025
1f3c339
update
Alekhya0824 Jan 2, 2025
4c32aaa
updated
Alekhya0824 Jan 2, 2025
cdb5494
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 2, 2025
6748180
update
Alekhya0824 Jan 2, 2025
9131860
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Jan 2, 2025
2504655
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 2, 2025
c6cb02a
updated
Alekhya0824 Jan 2, 2025
78d3552
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Jan 2, 2025
672aaab
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 2, 2025
0da708b
update
Alekhya0824 Jan 3, 2025
3f88532
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Jan 3, 2025
e78c712
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 3, 2025
93dcfea
update
Alekhya0824 Jan 3, 2025
1651908
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Jan 3, 2025
60fc440
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 3, 2025
234842a
update
Alekhya0824 Jan 3, 2025
5aef361
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 3, 2025
34e58ec
update
Alekhya0824 Jan 3, 2025
b8bba4d
update
Alekhya0824 Jan 7, 2025
e73a94e
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Jan 7, 2025
c494c39
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 7, 2025
cb8fd3d
Merge branch 'master' of https://github.com/Azure/Azure-Sentinel into…
vakohl Jan 7, 2025
27379c6
rename sample data file
vakohl Jan 7, 2025
adc8a98
removing EventVendor and EventProduct
vakohl Jan 7, 2025
4513e90
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 7, 2025
c272f2e
update
Alekhya0824 Jan 9, 2025
d1151c9
update
Alekhya0824 Jan 9, 2025
2642fcf
update
Alekhya0824 Jan 9, 2025
dcb686b
update
Alekhya0824 Jan 9, 2025
10d731f
Merge remote-tracking branch 'origin/master' into native_Authenticati…
Jan 9, 2025
2a90b5a
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 9, 2025
565807d
updated
Alekhya0824 Jan 9, 2025
ff9d3bf
Merge branch 'native_Authentication_parser' of https://github.com/Azu…
Alekhya0824 Jan 9, 2025
9a49735
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jan 9, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,26 @@
"name": "TimeGenerated",
"type": "DateTime"
},
{
"name": "_ItemId",
"type": "string"
},
{
"name": "TenantId",
"type": "string"
},
{
"name": "SourceSystem",
"type": "string"
},
{
"name": "_ResourceId",
"type": "string"
},
{
"name": "_SubscriptionId",
"type": "string"
},
{
"name": "AdditionalFields",
"type": "Dynamic"
Expand Down
Original file line number Diff line number Diff line change
@@ -1 +1,2 @@
ParserName
_Im_Authentication_Native
Original file line number Diff line number Diff line change
Expand Up @@ -27,10 +27,10 @@
"displayName": "Authentication ASIM parser",
"category": "ASIM",
"FunctionAlias": "ASimAuthentication",
"query": "let DisabledParsers=materialize(_GetWatchlist('ASimDisabledParsers') | where SearchKey in ('Any', 'ExcludeASimAuthentication') | extend SourceSpecificParser=column_ifexists('SourceSpecificParser','') | distinct SourceSpecificParser);\nlet ASimAuthenticationDisabled=toscalar('ExcludeASimAuthentication' in (DisabledParsers) or 'Any' in (DisabledParsers)); \nunion isfuzzy=true\n vimAuthenticationEmpty, \n ASimAuthenticationAADManagedIdentitySignInLogs (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationAADManagedIdentitySignInLogs' in (DisabledParsers) )),\n ASimAuthenticationAADNonInteractiveUserSignInLogs (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationAADNonInteractiveUserSignInLogs' in (DisabledParsers) )),\n ASimAuthenticationAADServicePrincipalSignInLogs (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationAADServicePrincipalSignInLogs' in (DisabledParsers) )),\n ASimAuthenticationAWSCloudTrail (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationAWSCloudTrail' in (DisabledParsers) )),\n ASimAuthenticationBarracudaWAF (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationBarracudaWAF' in (DisabledParsers) )),\n ASimAuthenticationCiscoASA (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationCiscoASA' in (DisabledParsers) )), \n ASimAuthenticationCiscoISE (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationCiscoISE' in (DisabledParsers) )),\n ASimAuthenticationCiscoMeraki (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationCiscoMeraki' in (DisabledParsers) )),\n ASimAuthenticationCiscoMerakiSyslog (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationCiscoMerakiSyslog' in (DisabledParsers) )),\n ASimAuthenticationM365Defender (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationM365Defender' in (DisabledParsers) )),\n ASimAuthenticationMD4IoT (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationMD4IoT' in (DisabledParsers) )),\n ASimAuthenticationMicrosoftWindowsEvent (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationMicrosoftWindowsEvent' in (DisabledParsers) )),\n ASimAuthenticationOktaSSO (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationOktaSSO' in (DisabledParsers) )),\n ASimAuthenticationOktaV2(ASimAuthenticationDisabled or ('ExcludeASimAuthenticationOktaV2' in (DisabledParsers) )),\n ASimAuthenticationPostgreSQL (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationPostgreSQL' in (DisabledParsers) )),\n ASimAuthenticationSigninLogs (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSigninLogs' in (DisabledParsers) )),\n ASimAuthenticationSshd (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSshd' in (DisabledParsers) )),\n ASimAuthenticationSu (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSu' in (DisabledParsers) )),\n ASimAuthenticationSudo (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSudo' in (DisabledParsers) )),\n ASimAuthenticationSalesforceSC (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSalesforceSC' in (DisabledParsers) )),\n ASimAuthenticationVectraXDRAudit (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationVectraXDRAudit' in (DisabledParsers) )),\n ASimAuthenticationSentinelOne (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSentinelOne' in (DisabledParsers) )),\n ASimAuthenticationGoogleWorkspace (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationGoogleWorkspace' in (DisabledParsers) )),\n ASimAuthenticationPaloAltoCortexDataLake (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationPaloAltoCortexDataLake' in (DisabledParsers) )),\n ASimAuthenticationVMwareCarbonBlackCloud (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationVMwareCarbonBlackCloud' in (DisabledParsers) )),\n ASimAuthenticationCrowdStrikeFalconHost (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationCrowdStrikeFalcon' in (DisabledParsers) )),\n ASimAuthenticationIllumioSaaSCore (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationIllumioSaaS' in (DisabledParsers) ))\n",
"query": "let DisabledParsers=materialize(_GetWatchlist('ASimDisabledParsers') | where SearchKey in ('Any', 'ExcludeASimAuthentication') | extend SourceSpecificParser=column_ifexists('SourceSpecificParser','') | distinct SourceSpecificParser);\nlet ASimAuthenticationDisabled=toscalar('ExcludeASimAuthentication' in (DisabledParsers) or 'Any' in (DisabledParsers)); \nunion isfuzzy=true\n vimAuthenticationEmpty, \n ASimAuthenticationAADManagedIdentitySignInLogs (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationAADManagedIdentitySignInLogs' in (DisabledParsers) )),\n ASimAuthenticationAADNonInteractiveUserSignInLogs (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationAADNonInteractiveUserSignInLogs' in (DisabledParsers) )),\n ASimAuthenticationAADServicePrincipalSignInLogs (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationAADServicePrincipalSignInLogs' in (DisabledParsers) )),\n ASimAuthenticationAWSCloudTrail (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationAWSCloudTrail' in (DisabledParsers) )),\n ASimAuthenticationBarracudaWAF (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationBarracudaWAF' in (DisabledParsers) )),\n ASimAuthenticationCiscoASA (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationCiscoASA' in (DisabledParsers) )), \n ASimAuthenticationCiscoISE (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationCiscoISE' in (DisabledParsers) )),\n ASimAuthenticationCiscoMeraki (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationCiscoMeraki' in (DisabledParsers) )),\n ASimAuthenticationCiscoMerakiSyslog (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationCiscoMerakiSyslog' in (DisabledParsers) )),\n ASimAuthenticationM365Defender (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationM365Defender' in (DisabledParsers) )),\n ASimAuthenticationMD4IoT (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationMD4IoT' in (DisabledParsers) )),\n ASimAuthenticationMicrosoftWindowsEvent (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationMicrosoftWindowsEvent' in (DisabledParsers) )),\n ASimAuthenticationOktaSSO (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationOktaSSO' in (DisabledParsers) )),\n ASimAuthenticationOktaV2(ASimAuthenticationDisabled or ('ExcludeASimAuthenticationOktaV2' in (DisabledParsers) )),\n ASimAuthenticationPostgreSQL (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationPostgreSQL' in (DisabledParsers) )),\n ASimAuthenticationSigninLogs (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSigninLogs' in (DisabledParsers) )),\n ASimAuthenticationSshd (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSshd' in (DisabledParsers) )),\n ASimAuthenticationSu (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSu' in (DisabledParsers) )),\n ASimAuthenticationSudo (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSudo' in (DisabledParsers) )),\n ASimAuthenticationSalesforceSC (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSalesforceSC' in (DisabledParsers) )),\n ASimAuthenticationVectraXDRAudit (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationVectraXDRAudit' in (DisabledParsers) )),\n ASimAuthenticationSentinelOne (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationSentinelOne' in (DisabledParsers) )),\n ASimAuthenticationGoogleWorkspace (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationGoogleWorkspace' in (DisabledParsers) )),\n ASimAuthenticationPaloAltoCortexDataLake (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationPaloAltoCortexDataLake' in (DisabledParsers) )),\n ASimAuthenticationVMwareCarbonBlackCloud (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationVMwareCarbonBlackCloud' in (DisabledParsers) )),\n ASimAuthenticationCrowdStrikeFalconHost (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationCrowdStrikeFalcon' in (DisabledParsers) )),\n ASimAuthenticationIllumioSaaSCore (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationIllumioSaaS' in (DisabledParsers) )),\n ASimAuthenticationNative (ASimAuthenticationDisabled or ('ExcludeASimAuthenticationNative' in (DisabledParsers) ))\n",
"version": 1,
"functionParameters": "disabled:bool=False"
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@
}
}
]
}
}
Loading
Loading