Back
Id97857198-99f2-48dd-b036-461d85a29570
RulenameUniqkey - Event ingestion stopped
DescriptionFires when the UniqkeyEvents_CL table has received no events for six consecutive hours. A silent feed can mean the data connector is failing, the API token has expired or been revoked, or the audit feed has been disabled on the Uniqkey side, and an attacker disabling logging looks identical to an operational outage, so the gap itself is treated as a security signal. Extend the query period if your organization is regularly quiet for longer stretches, for example over weekends.
SeverityMedium
TacticsDefenseEvasion
TechniquesT1562
Required data connectorsUniqkeyEventsConnector
KindScheduled
Query frequency1h
Query period6h
Trigger threshold0
Trigger operatorEqual
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Event%20ingestion%20stopped.yaml
Version1.0.0
Arm template97857198-99f2-48dd-b036-461d85a29570.json
Deploy To Azure
UniqkeyEvents_CL
| where TimeGenerated > ago(6h)
| take 1
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: 5h
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: false
  createIncident: true
name: Uniqkey - Event ingestion stopped
suppressionDuration: 5h
suppressionEnabled: false
triggerOperator: Equal
kind: Scheduled
queryFrequency: 1h
description: Fires when the UniqkeyEvents_CL table has received no events for six consecutive hours. A silent feed can mean the data connector is failing, the API token has expired or been revoked, or the audit feed has been disabled on the Uniqkey side, and an attacker disabling logging looks identical to an operational outage, so the gap itself is treated as a security signal. Extend the query period if your organization is regularly quiet for longer stretches, for example over weekends.
id: 97857198-99f2-48dd-b036-461d85a29570
triggerThreshold: 0
queryPeriod: 6h
query: |-
  UniqkeyEvents_CL
  | where TimeGenerated > ago(6h)
  | take 1
version: 1.0.0
requiredDataConnectors:
- connectorId: UniqkeyEventsConnector
  dataTypes:
  - UniqkeyEvents_CL
eventGroupingSettings:
  aggregationKind: SingleAlert
severity: Medium
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Event%20ingestion%20stopped.yaml
relevantTechniques:
- T1562
tactics:
- DefenseEvasion
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/97857198-99f2-48dd-b036-461d85a29570')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/97857198-99f2-48dd-b036-461d85a29570')]",
      "properties": {
        "alertRuleTemplateName": "97857198-99f2-48dd-b036-461d85a29570",
        "customDetails": null,
        "description": "Fires when the UniqkeyEvents_CL table has received no events for six consecutive hours. A silent feed can mean the data connector is failing, the API token has expired or been revoked, or the audit feed has been disabled on the Uniqkey side, and an attacker disabling logging looks identical to an operational outage, so the gap itself is treated as a security signal. Extend the query period if your organization is regularly quiet for longer stretches, for example over weekends.",
        "displayName": "Uniqkey - Event ingestion stopped",
        "enabled": true,
        "entityMappings": null,
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": false,
            "lookbackDuration": "PT5H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Uniqkey/Analytic%20Rules/Uniqkey%20-%20Event%20ingestion%20stopped.yaml",
        "query": "UniqkeyEvents_CL\n| where TimeGenerated > ago(6h)\n| take 1",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT6H",
        "severity": "Medium",
        "subTechniques": [],
        "suppressionDuration": "PT5H",
        "suppressionEnabled": false,
        "tactics": [
          "DefenseEvasion"
        ],
        "techniques": [
          "T1562"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "Equal",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}