let timeFrame = 10m;
datawizaserveraccess_CL
| where TimeGenerated between (ago(timeFrame) .. now())
and Status_d >= 500
| summarize Count = count()
| where Count > 100
query: |
let timeFrame = 10m;
datawizaserveraccess_CL
| where TimeGenerated between (ago(timeFrame) .. now())
and Status_d >= 500
| summarize Count = count()
| where Count > 100
queryFrequency: 10m
queryPeriod: 10m
triggerOperator: GreaterThan
eventGroupingSettings:
aggregationKind: SingleAlert
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Datawiza/Analytic Rules/DatawizaSentinelAlerts.yaml
tactics:
- Discovery
triggerThreshold: 0
requiredDataConnectors:
- connectorId: DatawizaDapSolution
dataTypes:
- datawizaserveraccess_CL
alertDetailsOverride:
alertDescriptionFormat: |
Detected {{Count}} errors within 10 minutes. Please investigate unauthorized access attempts or misconfigurations.
alertDisplayNameFormat: Datawiza Massive Error Detection
relevantTechniques:
- T1082
description: |
"This rule is designed to identify when the system is experiencing abnormal errors."
name: Datawiza - massive errors detected
version: 1.0.0
kind: Scheduled
id: ddee1398-cf0b-46af-b583-78c3c29156dc
severity: Medium