Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

VMware Edge Cloud Orchestrator - New LAN-Side Client Device Detected

Back
Id69c0644f-4ad5-41b6-9e09-a94c072ab80e
RulenameVMware Edge Cloud Orchestrator - New LAN-Side Client Device Detected
DescriptionThis analytics rule creates notifications of newly connected devices. These clients are connected to the LAN interface of the Edge.
SeverityInformational
Required data connectorsVMwareSDWAN
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sdwan-lanside-devicedetect.yaml
Version1.0.0
Arm template69c0644f-4ad5-41b6-9e09-a94c072ab80e.json
Deploy To Azure
VMware_VECO_EventLogs_CL
| extend details = todynamic(detail)
| evaluate bag_unpack(details)
| where event == "EDGE_NEW_DEVICE"
description: This analytics rule creates notifications of newly connected devices. These clients are connected to the LAN interface of the Edge.
version: 1.0.0
query: |+
  VMware_VECO_EventLogs_CL
  | extend details = todynamic(detail)
  | evaluate bag_unpack(details)
  | where event == "EDGE_NEW_DEVICE"  

triggerOperator: gt
kind: Scheduled
queryFrequency: 1h
customDetails:
  DHCP_Parameter_List: dhcp_param_list
  Client_MAC_Address: client_mac
triggerThreshold: 0
alertDetailsOverride:
  alertDynamicProperties: []
suppressionDuration: 5h
suppressionEnabled: false
entityMappings:
- fieldMappings:
  - identifier: HostName
    columnName: hostname
  - identifier: OSFamily
    columnName: os_description
  - identifier: OSVersion
    columnName: os_version
  entityType: Host
- fieldMappings:
  - identifier: Address
    columnName: client_ipv4addr
  entityType: IP
id: 69c0644f-4ad5-41b6-9e09-a94c072ab80e
queryPeriod: 1h
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: Informational
name: VMware Edge Cloud Orchestrator - New LAN-Side Client Device Detected
incidentConfiguration:
  groupingConfiguration:
    reopenClosedIncident: false
    groupByEntities: []
    groupByCustomDetails: []
    lookbackDuration: 1h
    enabled: true
    matchingMethod: AllEntities
    groupByAlertDetails: []
  createIncident: true
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sdwan-lanside-devicedetect.yaml
requiredDataConnectors:
- dataTypes:
  - SDWAN
  connectorId: VMwareSDWAN