VMware_CWS_DLPLogs_CL
| join kind=innerunique VMware_CWS_Weblogs_CL on TimeGenerated
name: VMware Cloud Web Security - Data Loss Prevention Violation
triggerOperator: gt
requiredDataConnectors:
- dataTypes:
- CWS
connectorId: VMwareSDWAN
description: This Analytics rule receives VMware CWS DLP alerts and combines them with their respective Web Log events. Each Data Loss Prevention event is an alert of policy violations and should be investigated.
queryPeriod: 1h
severity: Medium
eventGroupingSettings:
aggregationKind: AlertPerResult
suppressionDuration: 5h
id: d811ef72-66b9-43a3-ba29-cd9e4bf75b74
kind: Scheduled
suppressionEnabled: false
triggerThreshold: 0
query: |-
VMware_CWS_DLPLogs_CL
| join kind=innerunique VMware_CWS_Weblogs_CL on TimeGenerated
version: 1.0.0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sase-cwsdlp-violation.yaml
incidentConfiguration:
createIncident: true
groupingConfiguration:
enabled: true
groupByAlertDetails: []
groupByCustomDetails: []
groupByEntities: []
reopenClosedIncident: false
lookbackDuration: 5h
matchingMethod: AllEntities
queryFrequency: 1h
entityMappings:
- fieldMappings:
- identifier: Name
columnName: userId
entityType: Account
- fieldMappings:
- identifier: Address
columnName: sourceIp
entityType: IP
- fieldMappings:
- identifier: Name
columnName: casbAppName
entityType: CloudApplication
- fieldMappings:
- identifier: Url
columnName: dstUrl
entityType: URL
customDetails:
CWS_Rule_Name: ruleMatched
CWS_Policy_Name: policyName