Skip to content

Commit

Permalink
Repackage - Digital Guardian Data Loss Prevention
Browse files Browse the repository at this point in the history
  • Loading branch information
v-rusraut committed Dec 26, 2024
1 parent 11ce884 commit 3e3e2f4
Show file tree
Hide file tree
Showing 25 changed files with 115 additions and 681 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand All @@ -34,5 +31,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand All @@ -28,5 +25,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand All @@ -32,5 +29,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down Expand Up @@ -35,5 +32,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand All @@ -34,5 +31,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down Expand Up @@ -37,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand All @@ -31,5 +28,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand All @@ -29,5 +26,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand All @@ -28,5 +25,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: High
status: Available
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand All @@ -31,5 +28,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: AccountCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"Name": "Digital Guardian Data Loss Prevention",
"Author": "Microsoft - support@microsoft.com",
"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\" width=\"75px\" height=\"75px\">",
"Description": "The [Digital Guardian Data Loss Prevention (DLP)](https://digitalguardian.com/platform-overview) data connector provides the capability to ingest Digital Guardian DLP logs into Microsoft Sentinel.\n\n This solution is dependent on the Syslog solution containing the Syslog via AMA connector to collect the logs. The Syslog solution will be installed as part of this solution installation. \n\n **NOTE**: Microsoft recommends installation of Syslog via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024**. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).",
"Description": "The [Digital Guardian Data Loss Prevention (DLP)](https://digitalguardian.com/platform-overview) data connector provides the capability to ingest Digital Guardian DLP logs into Microsoft Sentinel.\n\n This solution is dependent on the Syslog solution containing the Syslog via AMA connector to collect the logs. The Syslog solution will be installed as part of this solution installation. \n\n **NOTE**: Microsoft recommends installation of Syslog via AMA Connector.Legacy connector uses the Log Analytics agent which were deprecated on **Aug 31, 2024.** Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).",
"Workbooks": [
"Workbooks/DigitalGuardian.json"
],
Expand Down Expand Up @@ -33,15 +33,12 @@
"Parsers": [
"Parsers/DigitalGuardianDLPEvent.yaml"
],
"Data Connectors": [
"Data Connectors/Connector_DigitalGuardian_Syslog.json"
],
"dependentDomainSolutionIds": [
"azuresentinel.azure-sentinel-solution-syslog"
],
"Metadata": "SolutionMetadata.json",
"BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\DigitalGuardianDLP",
"Version": "3.0.1",
"Version": "3.0.2",
"TemplateSpec": true,
"Is1PConnector": false
}
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query searches for incident domains.'
severity: Medium
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query searches for files sent by users.'
severity: Medium
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query searches for users' incidents.'
severity: Medium
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query searches for insecure file transfer sources.'
severity: Medium
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query searches for inspected files.'
severity: Medium
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query searches for new incidents.'
severity: Medium
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query searches for rare destination ports.'
severity: Medium
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query searches rare network protocols.'
severity: Medium
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query searches for rare Urls.'
severity: Medium
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query searches for URLs used.'
severity: Medium
requiredDataConnectors:
- connectorId: DigitalGuardianDLP
dataTypes:
- DigitalGuardianDLPEvent
- connectorId: SyslogAma
datatypes:
- Syslog
Expand Down
Binary file not shown.
Loading

0 comments on commit 3e3e2f4

Please sign in to comment.