Back
Idb54123ef-cfa7-769e-a959-f437404a1192
RulenameUniFi Site Manager: ISP Downtime
DescriptionIdentifies when the ISP connection experiences downtime, impacting business operations and requiring documentation for SLA purposes.
SeverityHigh
TacticsImpact
TechniquesT1489
T1499
Required data connectorsUniFiSiteManagerConnectorDefinition
KindScheduled
Query frequency15m
Query period30m
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudISPDowntime.yaml
Version1.0.1
Arm templateb54123ef-cfa7-769e-a959-f437404a1192.json
Deploy To Azure
// UniFi ISP Downtime Detection
let MinDowntimeSeconds = 60;
Unifi_SiteManager_ISPMetrics_CL
| where TimeGenerated > ago(30m)
| mv-expand period = Periods
| extend
    metricTime = todatetime(period.metricTime),
    downtime = toint(period.data.wan.downtime),
    uptime = todouble(period.data.wan.uptime),
    ispName = tostring(period.data.wan.ispName),
    ispAsn = tostring(period.data.wan.ispAsn)
// De-duplicate Periods: each poll returns the same hour buckets, so collapse to latest value per metricTime
| summarize arg_max(TimeGenerated, downtime, uptime, ispAsn) by tostring(SiteId), ispName, metricTime
| where metricTime > ago(30m)
| where downtime > 0
| summarize
    TotalDowntimeSeconds = sum(downtime),
    EventCount = count(),
    AvgUptime = round(avg(uptime), 2),
    FirstSeen = min(metricTime),
    LastSeen = max(metricTime)
    by SiteId, ispName, ispAsn
| where TotalDowntimeSeconds >= MinDowntimeSeconds
| extend
    TimeGenerated = now(),
    DowntimeMinutes = round(TotalDowntimeSeconds / 60.0, 2)
| project
    TimeGenerated,
    SiteId = SiteId,
    ISPName = ispName,
    ISPAsn = ispAsn,
    TotalDowntimeSeconds,
    DowntimeMinutes,
    AvgUptimePct = AvgUptime,
    EventCount,
    FirstSeen,
    LastSeen
subTechniques:
- T1499.002
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT4H
    reopenClosedIncident: true
    matchingMethod: AllEntities
    enabled: true
  createIncident: true
name: 'UniFi Site Manager: ISP Downtime'
triggerOperator: gt
query: |
  // UniFi ISP Downtime Detection
  let MinDowntimeSeconds = 60;
  Unifi_SiteManager_ISPMetrics_CL
  | where TimeGenerated > ago(30m)
  | mv-expand period = Periods
  | extend
      metricTime = todatetime(period.metricTime),
      downtime = toint(period.data.wan.downtime),
      uptime = todouble(period.data.wan.uptime),
      ispName = tostring(period.data.wan.ispName),
      ispAsn = tostring(period.data.wan.ispAsn)
  // De-duplicate Periods: each poll returns the same hour buckets, so collapse to latest value per metricTime
  | summarize arg_max(TimeGenerated, downtime, uptime, ispAsn) by tostring(SiteId), ispName, metricTime
  | where metricTime > ago(30m)
  | where downtime > 0
  | summarize
      TotalDowntimeSeconds = sum(downtime),
      EventCount = count(),
      AvgUptime = round(avg(uptime), 2),
      FirstSeen = min(metricTime),
      LastSeen = max(metricTime)
      by SiteId, ispName, ispAsn
  | where TotalDowntimeSeconds >= MinDowntimeSeconds
  | extend
      TimeGenerated = now(),
      DowntimeMinutes = round(TotalDowntimeSeconds / 60.0, 2)
  | project
      TimeGenerated,
      SiteId = SiteId,
      ISPName = ispName,
      ISPAsn = ispAsn,
      TotalDowntimeSeconds,
      DowntimeMinutes,
      AvgUptimePct = AvgUptime,
      EventCount,
      FirstSeen,
      LastSeen
queryFrequency: 15m
description: |
  Identifies when the ISP connection experiences downtime, impacting business operations and requiring documentation for SLA purposes.
id: b54123ef-cfa7-769e-a959-f437404a1192
triggerThreshold: 0
queryPeriod: 30m
version: 1.0.1
kind: Scheduled
status: Available
severity: High
requiredDataConnectors:
- connectorId: UniFiSiteManagerConnectorDefinition
  dataTypes:
  - Unifi_SiteManager_ISPMetrics_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudISPDowntime.yaml
relevantTechniques:
- T1489
- T1499
tactics:
- Impact
entityMappings:
- fieldMappings:
  - identifier: HostName
    columnName: SiteId
  entityType: Host
- fieldMappings:
  - identifier: Name
    columnName: ISPName
  entityType: CloudApplication
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/b54123ef-cfa7-769e-a959-f437404a1192')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/b54123ef-cfa7-769e-a959-f437404a1192')]",
      "properties": {
        "alertRuleTemplateName": "b54123ef-cfa7-769e-a959-f437404a1192",
        "customDetails": null,
        "description": "Identifies when the ISP connection experiences downtime, impacting business operations and requiring documentation for SLA purposes.\n",
        "displayName": "UniFi Site Manager: ISP Downtime",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "SiteId",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "CloudApplication",
            "fieldMappings": [
              {
                "columnName": "ISPName",
                "identifier": "Name"
              }
            ]
          }
        ],
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT4H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": true
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudISPDowntime.yaml",
        "query": "// UniFi ISP Downtime Detection\nlet MinDowntimeSeconds = 60;\nUnifi_SiteManager_ISPMetrics_CL\n| where TimeGenerated > ago(30m)\n| mv-expand period = Periods\n| extend\n    metricTime = todatetime(period.metricTime),\n    downtime = toint(period.data.wan.downtime),\n    uptime = todouble(period.data.wan.uptime),\n    ispName = tostring(period.data.wan.ispName),\n    ispAsn = tostring(period.data.wan.ispAsn)\n// De-duplicate Periods: each poll returns the same hour buckets, so collapse to latest value per metricTime\n| summarize arg_max(TimeGenerated, downtime, uptime, ispAsn) by tostring(SiteId), ispName, metricTime\n| where metricTime > ago(30m)\n| where downtime > 0\n| summarize\n    TotalDowntimeSeconds = sum(downtime),\n    EventCount = count(),\n    AvgUptime = round(avg(uptime), 2),\n    FirstSeen = min(metricTime),\n    LastSeen = max(metricTime)\n    by SiteId, ispName, ispAsn\n| where TotalDowntimeSeconds >= MinDowntimeSeconds\n| extend\n    TimeGenerated = now(),\n    DowntimeMinutes = round(TotalDowntimeSeconds / 60.0, 2)\n| project\n    TimeGenerated,\n    SiteId = SiteId,\n    ISPName = ispName,\n    ISPAsn = ispAsn,\n    TotalDowntimeSeconds,\n    DowntimeMinutes,\n    AvgUptimePct = AvgUptime,\n    EventCount,\n    FirstSeen,\n    LastSeen\n",
        "queryFrequency": "PT15M",
        "queryPeriod": "PT30M",
        "severity": "High",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "Impact"
        ],
        "techniques": [
          "T1489",
          "T1499"
        ],
        "templateVersion": "1.0.1",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}