Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

VMware ESXi - Low patch disk space

Back
Id48d992ba-d404-4159-a8c6-46f51d1325c7
RulenameVMware ESXi - Low patch disk space
DescriptionThis rule is triggered when low patch disk store space is detected.
SeverityMedium
TacticsImpact
TechniquesT1529
Required data connectorsSyslogAma
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMWareESXi/Analytic Rules/ESXiLowPatchDiskSpace.yaml
Version1.0.2
Arm template48d992ba-d404-4159-a8c6-46f51d1325c7.json
Deploy To Azure
let threshold = 100;
VMwareESXi
| where SyslogMessage has ('Patch store disk')
| extend sp = toreal(extract(@'free space is:\s(\d+)', 1, SyslogMessage)) / 1000000000
| where sp < threshold
| extend h = 'Hypervisor'
| extend HostCustomEntity = h
entityMappings:
- fieldMappings:
  - columnName: HostCustomEntity
    identifier: FullName
  entityType: Host
triggerOperator: gt
tactics:
- Impact
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMWareESXi/Analytic Rules/ESXiLowPatchDiskSpace.yaml
version: 1.0.2
query: |
  let threshold = 100;
  VMwareESXi
  | where SyslogMessage has ('Patch store disk')
  | extend sp = toreal(extract(@'free space is:\s(\d+)', 1, SyslogMessage)) / 1000000000
  | where sp < threshold
  | extend h = 'Hypervisor'
  | extend HostCustomEntity = h  
triggerThreshold: 0
relevantTechniques:
- T1529
queryPeriod: 1h
status: Available
severity: Medium
kind: Scheduled
name: VMware ESXi - Low patch disk space
queryFrequency: 1h
id: 48d992ba-d404-4159-a8c6-46f51d1325c7
description: |
    'This rule is triggered when low patch disk store space is detected.'
requiredDataConnectors:
- datatypes:
  - Syslog
  connectorId: SyslogAma