VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
tactics:
- Impact
triggerOperator: gt
queryPeriod: 1h
queryFrequency: 1h
requiredDataConnectors:
- dataTypes:
- SDWAN
connectorId: VMwareSDWAN
id: a88ead0a-f022-48d6-8f53-e5a164c4c72e
relevantTechniques:
- T1498
eventGroupingSettings:
aggregationKind: SingleAlert
triggerThreshold: 0
suppressionEnabled: false
kind: Scheduled
query: |-
VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
customDetails:
edgeSerialNumber: edgeSerialNumber
name: VMware SD-WAN Edge - Device Congestion Alert - Packet Drops
version: 1.0.0
suppressionDuration: 5h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sdwan-device-congestion.yaml
severity: Medium
incidentConfiguration:
groupingConfiguration:
enabled: true
groupByEntities: []
lookbackDuration: 5h
groupByAlertDetails: []
matchingMethod: AllEntities
reopenClosedIncident: false
groupByCustomDetails: []
createIncident: true
description: The VMware Edge Cloud Orchestrator reported an edge congestion event, where the Edge is dropping a large number of packets on one of its interfaces. This could indicate an ongoing Denial of Service attack against an appliance. Please make sure that Network Flood Protection is turned on.