VMware_CWS_DLPLogs_CL
| join kind=innerunique VMware_CWS_Weblogs_CL on TimeGenerated
name: VMware Cloud Web Security - Data Loss Prevention Violation
incidentConfiguration:
groupingConfiguration:
reopenClosedIncident: false
groupByCustomDetails: []
groupByAlertDetails: []
enabled: true
matchingMethod: AllEntities
groupByEntities: []
lookbackDuration: 5h
createIncident: true
query: |-
VMware_CWS_DLPLogs_CL
| join kind=innerunique VMware_CWS_Weblogs_CL on TimeGenerated
queryPeriod: 1h
triggerOperator: gt
suppressionEnabled: false
suppressionDuration: 5h
kind: Scheduled
triggerThreshold: 0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/VMware SD-WAN and SASE/Analytic Rules/vmw-sase-cwsdlp-violation.yaml
eventGroupingSettings:
aggregationKind: AlertPerResult
id: d811ef72-66b9-43a3-ba29-cd9e4bf75b74
customDetails:
CWS_Policy_Name: policyName
CWS_Rule_Name: ruleMatched
severity: Medium
requiredDataConnectors:
- connectorId: VMwareSDWAN
dataTypes:
- CWS
version: 1.0.0
description: This Analytics rule receives VMware CWS DLP alerts and combines them with their respective Web Log events. Each Data Loss Prevention event is an alert of policy violations and should be investigated.
entityMappings:
- entityType: Account
fieldMappings:
- columnName: userId
identifier: Name
- entityType: IP
fieldMappings:
- columnName: sourceIp
identifier: Address
- entityType: CloudApplication
fieldMappings:
- columnName: casbAppName
identifier: Name
- entityType: URL
fieldMappings:
- columnName: dstUrl
identifier: Url
queryFrequency: 1h