VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
name: VMware SD-WAN Edge - Device Congestion Alert - Packet Drops
queryPeriod: 1h
triggerOperator: gt
kind: Scheduled
id: a88ead0a-f022-48d6-8f53-e5a164c4c72e
eventGroupingSettings:
aggregationKind: SingleAlert
requiredDataConnectors:
- dataTypes:
- SDWAN
connectorId: VMwareSDWAN
suppressionDuration: 5h
description: The VMware Edge Cloud Orchestrator reported an edge congestion event, where the Edge is dropping a large number of packets on one of its interfaces. This could indicate an ongoing Denial of Service attack against an appliance. Please make sure that Network Flood Protection is turned on.
incidentConfiguration:
groupingConfiguration:
groupByAlertDetails: []
enabled: true
reopenClosedIncident: false
groupByCustomDetails: []
lookbackDuration: 5h
groupByEntities: []
matchingMethod: AllEntities
createIncident: true
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sdwan-device-congestion.yaml
queryFrequency: 1h
triggerThreshold: 0
severity: Medium
version: 1.0.0
tactics:
- Impact
customDetails:
edgeSerialNumber: edgeSerialNumber
suppressionEnabled: false
query: |-
VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
relevantTechniques:
- T1498