VMware_CWS_DLPLogs_CL
| join kind=innerunique VMware_CWS_Weblogs_CL on TimeGenerated
kind: Scheduled
triggerThreshold: 0
triggerOperator: gt
version: 1.0.0
incidentConfiguration:
createIncident: true
groupingConfiguration:
reopenClosedIncident: false
enabled: true
matchingMethod: AllEntities
groupByAlertDetails: []
groupByEntities: []
groupByCustomDetails: []
lookbackDuration: 5h
suppressionDuration: 5h
queryFrequency: 1h
id: d811ef72-66b9-43a3-ba29-cd9e4bf75b74
requiredDataConnectors:
- connectorId: VMwareSDWAN
dataTypes:
- CWS
suppressionEnabled: false
name: VMware Cloud Web Security - Data Loss Prevention Violation
description: This Analytics rule receives VMware CWS DLP alerts and combines them with their respective Web Log events. Each Data Loss Prevention event is an alert of policy violations and should be investigated.
customDetails:
CWS_Rule_Name: ruleMatched
CWS_Policy_Name: policyName
entityMappings:
- entityType: Account
fieldMappings:
- columnName: userId
identifier: Name
- entityType: IP
fieldMappings:
- columnName: sourceIp
identifier: Address
- entityType: CloudApplication
fieldMappings:
- columnName: casbAppName
identifier: Name
- entityType: URL
fieldMappings:
- columnName: dstUrl
identifier: Url
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sase-cwsdlp-violation.yaml
queryPeriod: 1h
severity: Medium
query: |-
VMware_CWS_DLPLogs_CL
| join kind=innerunique VMware_CWS_Weblogs_CL on TimeGenerated
eventGroupingSettings:
aggregationKind: AlertPerResult