VMware_VECO_EventLogs_CL
| where event == "CWS_EVENT"
| extend cwsPolicyAction = todynamic(detail).subEvent
| where cwsPolicyAction contains "SECURITY_RULE"
| extend cwsRuleName = todynamic(detail).name
| extend cwsRuleType = todynamic(detail).data.ruleType
| extend cwsPolicyName = todynamic(detail).policyName
description: This Analytics rule provides notifications when a VMware CWS policy has been modified. These alerts serve audit purposes. Policy changes might lower the level of security controls.
query: |+
VMware_VECO_EventLogs_CL
| where event == "CWS_EVENT"
| extend cwsPolicyAction = todynamic(detail).subEvent
| where cwsPolicyAction contains "SECURITY_RULE"
| extend cwsRuleName = todynamic(detail).name
| extend cwsRuleType = todynamic(detail).data.ruleType
| extend cwsPolicyName = todynamic(detail).policyName
severity: Informational
triggerThreshold: 0
queryFrequency: 1h
queryPeriod: 1h
eventGroupingSettings:
aggregationKind: AlertPerResult
id: 3efebd49-c985-431b-9da8-d7d397092d18
name: VMware Cloud Web Security - Policy Change Detected
incidentConfiguration:
createIncident: true
groupingConfiguration:
reopenClosedIncident: false
groupByCustomDetails: []
enabled: true
matchingMethod: AllEntities
groupByAlertDetails: []
groupByEntities: []
lookbackDuration: 1h
kind: Scheduled
triggerOperator: gt
suppressionEnabled: false
suppressionDuration: 5h
version: 1.0.0
alertDetailsOverride:
alertDynamicProperties:
- value: cwsRuleType
alertProperty: ProductComponentName
alertDescriptionFormat: |+
CWS Policy Change Detected:
CWS Policy Name: {{cwsPolicyName}}
- Rule changed: {{cwsRuleName}}
- Audited Action: {{cwsPolicyAction}}
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sase-cws-policychange.yaml
requiredDataConnectors:
- dataTypes:
- CWS
connectorId: VMwareSDWAN