VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
description: The VMware Edge Cloud Orchestrator reported an edge congestion event, where the Edge is dropping a large number of packets on one of its interfaces. This could indicate an ongoing Denial of Service attack against an appliance. Please make sure that Network Flood Protection is turned on.
tactics:
- Impact
suppressionEnabled: false
suppressionDuration: 5h
requiredDataConnectors:
- dataTypes:
- SDWAN
connectorId: VMwareSDWAN
incidentConfiguration:
groupingConfiguration:
reopenClosedIncident: false
groupByAlertDetails: []
lookbackDuration: 5h
groupByEntities: []
groupByCustomDetails: []
enabled: true
matchingMethod: AllEntities
createIncident: true
id: a88ead0a-f022-48d6-8f53-e5a164c4c72e
severity: Medium
eventGroupingSettings:
aggregationKind: SingleAlert
customDetails:
edgeSerialNumber: edgeSerialNumber
query: |-
VMware_VECO_EventLogs_CL
| where event == "EDGE_CONGESTED"
| where message contains "high number of packet drops"
| extend edgeSerialNumber = extract("edgeSerialNumber: (.+)$", 1, detail)
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sdwan-device-congestion.yaml
kind: Scheduled
queryPeriod: 1h
name: VMware SD-WAN Edge - Device Congestion Alert - Packet Drops
queryFrequency: 1h
triggerThreshold: 0
relevantTechniques:
- T1498
version: 1.0.0
triggerOperator: gt