Back
Id6f2d71d6-e6c4-0da4-91da-e8192dc5b12c
RulenameUniFi Site Manager: ISP Packet Loss
DescriptionIdentifies when WAN packet loss occurs. Even small loss percentages can significantly degrade VoIP calls and video conferencing quality.
SeverityMedium
TacticsImpact
TechniquesT1498
T1499
Required data connectorsUniFiSiteManagerConnectorDefinition
KindScheduled
Query frequency15m
Query period30m
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudISPPacketLoss.yaml
Version1.0.1
Arm template6f2d71d6-e6c4-0da4-91da-e8192dc5b12c.json
Deploy To Azure
// UniFi ISP Packet Loss Detection
let PacketLossThreshold = 5;
let MinTotalPacketLoss = 10;
Unifi_SiteManager_ISPMetrics_CL
| where TimeGenerated > ago(30m)
| mv-expand period = Periods
| extend
    metricTime = todatetime(period.metricTime),
    packetLoss = toint(period.data.wan.packetLoss),
    ispName = tostring(period.data.wan.ispName),
    ispAsn = tostring(period.data.wan.ispAsn),
    avgLatency = toint(period.data.wan.avgLatency)
// De-duplicate Periods: each poll returns the same hour buckets, so collapse to latest value per metricTime
| summarize arg_max(TimeGenerated, packetLoss, avgLatency, ispAsn) by tostring(SiteId), ispName, metricTime
| where metricTime > ago(30m)
| where packetLoss >= PacketLossThreshold
| summarize
    TotalPacketLoss = sum(packetLoss),
    EventCount = count(),
    AvgLatency = avg(avgLatency),
    FirstSeen = min(metricTime),
    LastSeen = max(metricTime)
    by SiteId, ispName, ispAsn
| where TotalPacketLoss >= MinTotalPacketLoss
| extend TimeGenerated = now()
| project
    TimeGenerated,
    SiteId = SiteId,
    ISPName = ispName,
    ISPAsn = ispAsn,
    TotalPacketLoss,
    EventCount,
    AvgLatencyMs = round(AvgLatency, 1),
    FirstSeen,
    LastSeen
subTechniques:
- T1498.001
- T1499.002
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT4H
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: true
  createIncident: true
name: 'UniFi Site Manager: ISP Packet Loss'
triggerOperator: gt
query: |
  // UniFi ISP Packet Loss Detection
  let PacketLossThreshold = 5;
  let MinTotalPacketLoss = 10;
  Unifi_SiteManager_ISPMetrics_CL
  | where TimeGenerated > ago(30m)
  | mv-expand period = Periods
  | extend
      metricTime = todatetime(period.metricTime),
      packetLoss = toint(period.data.wan.packetLoss),
      ispName = tostring(period.data.wan.ispName),
      ispAsn = tostring(period.data.wan.ispAsn),
      avgLatency = toint(period.data.wan.avgLatency)
  // De-duplicate Periods: each poll returns the same hour buckets, so collapse to latest value per metricTime
  | summarize arg_max(TimeGenerated, packetLoss, avgLatency, ispAsn) by tostring(SiteId), ispName, metricTime
  | where metricTime > ago(30m)
  | where packetLoss >= PacketLossThreshold
  | summarize
      TotalPacketLoss = sum(packetLoss),
      EventCount = count(),
      AvgLatency = avg(avgLatency),
      FirstSeen = min(metricTime),
      LastSeen = max(metricTime)
      by SiteId, ispName, ispAsn
  | where TotalPacketLoss >= MinTotalPacketLoss
  | extend TimeGenerated = now()
  | project
      TimeGenerated,
      SiteId = SiteId,
      ISPName = ispName,
      ISPAsn = ispAsn,
      TotalPacketLoss,
      EventCount,
      AvgLatencyMs = round(AvgLatency, 1),
      FirstSeen,
      LastSeen
queryFrequency: 15m
description: |
  Identifies when WAN packet loss occurs. Even small loss percentages can significantly degrade VoIP calls and video conferencing quality.
id: 6f2d71d6-e6c4-0da4-91da-e8192dc5b12c
triggerThreshold: 0
queryPeriod: 30m
version: 1.0.1
kind: Scheduled
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: UniFiSiteManagerConnectorDefinition
  dataTypes:
  - Unifi_SiteManager_ISPMetrics_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudISPPacketLoss.yaml
relevantTechniques:
- T1498
- T1499
tactics:
- Impact
entityMappings:
- fieldMappings:
  - identifier: HostName
    columnName: SiteId
  entityType: Host
- fieldMappings:
  - identifier: Name
    columnName: ISPName
  entityType: CloudApplication
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/6f2d71d6-e6c4-0da4-91da-e8192dc5b12c')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/6f2d71d6-e6c4-0da4-91da-e8192dc5b12c')]",
      "properties": {
        "alertRuleTemplateName": "6f2d71d6-e6c4-0da4-91da-e8192dc5b12c",
        "customDetails": null,
        "description": "Identifies when WAN packet loss occurs. Even small loss percentages can significantly degrade VoIP calls and video conferencing quality.\n",
        "displayName": "UniFi Site Manager: ISP Packet Loss",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "SiteId",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "CloudApplication",
            "fieldMappings": [
              {
                "columnName": "ISPName",
                "identifier": "Name"
              }
            ]
          }
        ],
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT4H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudISPPacketLoss.yaml",
        "query": "// UniFi ISP Packet Loss Detection\nlet PacketLossThreshold = 5;\nlet MinTotalPacketLoss = 10;\nUnifi_SiteManager_ISPMetrics_CL\n| where TimeGenerated > ago(30m)\n| mv-expand period = Periods\n| extend\n    metricTime = todatetime(period.metricTime),\n    packetLoss = toint(period.data.wan.packetLoss),\n    ispName = tostring(period.data.wan.ispName),\n    ispAsn = tostring(period.data.wan.ispAsn),\n    avgLatency = toint(period.data.wan.avgLatency)\n// De-duplicate Periods: each poll returns the same hour buckets, so collapse to latest value per metricTime\n| summarize arg_max(TimeGenerated, packetLoss, avgLatency, ispAsn) by tostring(SiteId), ispName, metricTime\n| where metricTime > ago(30m)\n| where packetLoss >= PacketLossThreshold\n| summarize\n    TotalPacketLoss = sum(packetLoss),\n    EventCount = count(),\n    AvgLatency = avg(avgLatency),\n    FirstSeen = min(metricTime),\n    LastSeen = max(metricTime)\n    by SiteId, ispName, ispAsn\n| where TotalPacketLoss >= MinTotalPacketLoss\n| extend TimeGenerated = now()\n| project\n    TimeGenerated,\n    SiteId = SiteId,\n    ISPName = ispName,\n    ISPAsn = ispAsn,\n    TotalPacketLoss,\n    EventCount,\n    AvgLatencyMs = round(AvgLatency, 1),\n    FirstSeen,\n    LastSeen\n",
        "queryFrequency": "PT15M",
        "queryPeriod": "PT30M",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Impact"
        ],
        "techniques": [
          "T1498",
          "T1499"
        ],
        "templateVersion": "1.0.1",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}