Armorblox_CL
| where remediation_actions_s contains "Needs Review"
| extend users_json = parse_json(users_s)
| extend Name = users_json[0].name, Email = users_json[0].email
| project-away users_json
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Armorblox/Analytic Rules/ArmorbloxNeedsReviewAlert.yaml
queryPeriod: 10m
description: |
'This rule generates an alert for an Armorblox incident where the remediation action is "Needs Review".'
triggerThreshold: 0
name: Armorblox Needs Review Alert
triggerOperator: GreaterThan
entityMappings:
- entityType: Mailbox
fieldMappings:
- identifier: MailboxPrimaryAddress
columnName: Email
- identifier: DisplayName
columnName: Name
kind: Scheduled
requiredDataConnectors:
- connectorId: Armorblox
dataTypes:
- Armorblox_CL
customDetails:
RemediationAction: remediation_actions_s
IncidentId: id_s
eventGroupingSettings:
aggregationKind: AlertPerResult
queryFrequency: 10m
tactics: []
id: 322d4765-be6b-4868-9e3f-138a4f339dd6
status: Available
version: 1.0.2
query: |
Armorblox_CL
| where remediation_actions_s contains "Needs Review"
| extend users_json = parse_json(users_s)
| extend Name = users_json[0].name, Email = users_json[0].email
| project-away users_json
alertDetailsOverride:
alertDescriptionFormat: 'Incident {{id_s}} generated at {{date_t}} needs review '
alertDisplayNameFormat: Alert from Armorblox
alertSeverityColumnName: priority_s
severity: Medium
relevantTechniques: []