VMware_CWS_DLPLogs_CL
| join kind=innerunique VMware_CWS_Weblogs_CL on TimeGenerated
requiredDataConnectors:
- connectorId: VMwareSDWAN
dataTypes:
- CWS
name: VMware Cloud Web Security - Data Loss Prevention Violation
queryFrequency: 1h
incidentConfiguration:
groupingConfiguration:
groupByEntities: []
matchingMethod: AllEntities
enabled: true
groupByCustomDetails: []
lookbackDuration: 5h
groupByAlertDetails: []
reopenClosedIncident: false
createIncident: true
triggerThreshold: 0
severity: Medium
query: |-
VMware_CWS_DLPLogs_CL
| join kind=innerunique VMware_CWS_Weblogs_CL on TimeGenerated
suppressionDuration: 5h
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sase-cwsdlp-violation.yaml
version: 1.0.0
entityMappings:
- fieldMappings:
- columnName: userId
identifier: Name
entityType: Account
- fieldMappings:
- columnName: sourceIp
identifier: Address
entityType: IP
- fieldMappings:
- columnName: casbAppName
identifier: Name
entityType: CloudApplication
- fieldMappings:
- columnName: dstUrl
identifier: Url
entityType: URL
queryPeriod: 1h
triggerOperator: gt
customDetails:
CWS_Policy_Name: policyName
CWS_Rule_Name: ruleMatched
suppressionEnabled: false
eventGroupingSettings:
aggregationKind: AlertPerResult
id: d811ef72-66b9-43a3-ba29-cd9e4bf75b74
kind: Scheduled
description: This Analytics rule receives VMware CWS DLP alerts and combines them with their respective Web Log events. Each Data Loss Prevention event is an alert of policy violations and should be investigated.