VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
customDetails:
edgeSerialNumber: edgeSerialNumber
name: VMware SD-WAN Edge - Device Congestion Alert - Packet Drops
relevantTechniques:
- T1498
id: a88ead0a-f022-48d6-8f53-e5a164c4c72e
suppressionEnabled: false
requiredDataConnectors:
- dataTypes:
- SDWAN
connectorId: VMwareSDWAN
eventGroupingSettings:
aggregationKind: SingleAlert
version: 1.0.0
severity: Medium
triggerThreshold: 0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sdwan-device-congestion.yaml
queryPeriod: 1h
incidentConfiguration:
groupingConfiguration:
groupByAlertDetails: []
lookbackDuration: 5h
reopenClosedIncident: false
groupByCustomDetails: []
groupByEntities: []
matchingMethod: AllEntities
enabled: true
createIncident: true
queryFrequency: 1h
suppressionDuration: 5h
query: |-
VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
tactics:
- Impact
kind: Scheduled
description: The VMware Edge Cloud Orchestrator reported an edge congestion event, where the Edge is dropping a large number of packets on one of its interfaces. This could indicate an ongoing Denial of Service attack against an appliance. Please make sure that Network Flood Protection is turned on.
triggerOperator: gt