{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/04e36dfa-05b3-45bd-b39f-28b6fac71337')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/04e36dfa-05b3-45bd-b39f-28b6fac71337')]",
      "properties": {
        "alertRuleTemplateName": "04e36dfa-05b3-45bd-b39f-28b6fac71337",
        "customDetails": null,
        "description": "Detects Netskope DLP (Data Loss Prevention) alerts raised with high or critical severity.\nThese alerts indicate sensitive data (e.g. PII, source code, financial records) matched a\nDLP policy during upload, download, or sharing and may represent data exfiltration.\n",
        "displayName": "Netskope - High Severity DLP Alert",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "User",
                "identifier": "Name"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "UserIp",
                "identifier": "Address"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "HostName",
                "identifier": "HostName"
              }
            ]
          }
        ],
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Netskopev2/Analytic%20Rules/NetskopeAlertsEvents_HighSeverityDLPAlert.yaml",
        "query": "NetskopeAlerts_CL\n| where TimeGenerated > ago(1h)\n| where alert_type =~ \"dlp\"\n| where severity has_any (\"high\", \"critical\")\n| summarize\n    AlertCount = count(),\n    DlpRules = make_set(dlp_rule, 20),\n    DlpProfiles = make_set(dlp_profile, 20),\n    Apps = make_set(app, 20),\n    FilePaths = make_set(file_path, 20),\n    FirstSeen = min(TimeGenerated),\n    LastSeen = max(TimeGenerated)\n    by User = user, UserIp = userip, HostName = hostname, AlertName = alert_name, Severity = severity\n| order by AlertCount desc\n| project\n    LastSeen,\n    AlertName,\n    Severity,\n    User,\n    UserIp,\n    HostName,\n    AlertCount,\n    Apps,\n    DlpRules,\n    DlpProfiles,\n    FilePaths,\n    FirstSeen\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Collection",
          "Exfiltration"
        ],
        "techniques": [
          "T1005",
          "T1567"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}
