VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
tactics:
- Impact
triggerOperator: gt
requiredDataConnectors:
- connectorId: VMwareSDWAN
dataTypes:
- SDWAN
relevantTechniques:
- T1498
suppressionDuration: 5h
id: a88ead0a-f022-48d6-8f53-e5a164c4c72e
queryPeriod: 1h
name: VMware SD-WAN Edge - Device Congestion Alert - Packet Drops
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sdwan-device-congestion.yaml
triggerThreshold: 0
description: The VMware Edge Cloud Orchestrator reported an edge congestion event, where the Edge is dropping a large number of packets on one of its interfaces. This could indicate an ongoing Denial of Service attack against an appliance. Please make sure that Network Flood Protection is turned on.
customDetails:
edgeSerialNumber: edgeSerialNumber
suppressionEnabled: false
version: 1.0.0
query: |-
VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
incidentConfiguration:
groupingConfiguration:
groupByAlertDetails: []
lookbackDuration: 5h
matchingMethod: AllEntities
groupByEntities: []
groupByCustomDetails: []
reopenClosedIncident: false
enabled: true
createIncident: true
queryFrequency: 1h
severity: Medium
eventGroupingSettings:
aggregationKind: SingleAlert
kind: Scheduled