Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Azure WAF Sentinel solution does not query resource specific table #11434

Open
tschleining opened this issue Nov 14, 2024 · 6 comments
Open

Azure WAF Sentinel solution does not query resource specific table #11434

tschleining opened this issue Nov 14, 2024 · 6 comments
Assignees
Labels
feature request Solution Solution specialty review needed

Comments

@tschleining
Copy link

The Azure Web Application Firewall solution for Sentinel currently queries the AzureDiagnostics table and not the "new" resource specific AGWFirewallLogs table

Ideally the solution would allow for both locations to be queried regardless of what diagnostic setting is set for the WAF resource.

@v-sudkharat v-sudkharat added the Solution Solution specialty review needed label Nov 15, 2024
@v-shukore
Copy link
Contributor

Hi @tschleining, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates. Thanks!!

@v-shukore
Copy link
Contributor

Hi @tschleining, could you please provide more information regarding this issue? Clarifying these details will help us resolve it more effectively. Thanks!!

@v-visodadasi v-visodadasi removed their assignment Dec 4, 2024
@v-shukore
Copy link
Contributor

Hi @tschleining, please provide more information regarding this issue. Thanks!!

@bedij03
Copy link

bedij03 commented Dec 16, 2024

Hi @v-shukore - We are having the same issue.
Application Gateway resource specific tables for Diagnostic settings went GA in August, 2024.
https://azure.microsoft.com/en-us/updates?id=dedicated-log-analytics-tables-in-application-gateway

However, the sentinel connector for WAF is still quering on the AzureDiagnostics table as per the following json config.
https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Azure%20Web%20Application%20Firewall%20(WAF)/Data%20Connectors/template_WAF.JSON

Any timeline as to when the connector will be updated so that we can start using dedicated tables instead ?

Thanks!

@v-shukore
Copy link
Contributor

Hi @bedij03,

Thanks for your response.

Currently, we don't have a plan to update the connector. We will share updates with the teams once we receive any update from them will update on GitHub accordingly. Meanwhile, you can follow the steps mentioned in the document for dedicated Application Gateway resource-specific tables.
https://learn.microsoft.com/en-us/azure/application-gateway/application-gateway-diagnostics#storage-locations
https://learn.microsoft.com/en-us/azure/application-gateway/monitor-application-gateway-reference#resource-logs

@v-shukore
Copy link
Contributor

Hi @tschleining @bedij03, Gentle Reminder: We are waiting for your response on this issue. If you still need to keep this issue active, please respond to it in the next 2 days. If we don't receive a response by 29-12-2024 date, we will be closing this issue.
Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature request Solution Solution specialty review needed
Projects
None yet
Development

No branches or pull requests

5 participants