VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
description: The VMware Edge Cloud Orchestrator reported an edge congestion event, where the Edge is dropping a large number of packets on one of its interfaces. This could indicate an ongoing Denial of Service attack against an appliance. Please make sure that Network Flood Protection is turned on.
incidentConfiguration:
groupingConfiguration:
groupByCustomDetails: []
groupByEntities: []
reopenClosedIncident: false
matchingMethod: AllEntities
enabled: true
lookbackDuration: 5h
groupByAlertDetails: []
createIncident: true
suppressionEnabled: false
suppressionDuration: 5h
requiredDataConnectors:
- dataTypes:
- SDWAN
connectorId: VMwareSDWAN
eventGroupingSettings:
aggregationKind: SingleAlert
query: |-
VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
queryPeriod: 1h
tactics:
- Impact
triggerThreshold: 0
triggerOperator: gt
version: 1.0.0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sdwan-device-congestion.yaml
name: VMware SD-WAN Edge - Device Congestion Alert - Packet Drops
severity: Medium
relevantTechniques:
- T1498
id: a88ead0a-f022-48d6-8f53-e5a164c4c72e
kind: Scheduled
customDetails:
edgeSerialNumber: edgeSerialNumber
queryFrequency: 1h