let timeFrame = 10m;
datawizaserveraccess_CL
| where TimeGenerated between (ago(timeFrame) .. now())
and Status_d >= 500
| summarize Count = count()
| where Count > 100
relevantTechniques:
- T1082
eventGroupingSettings:
aggregationKind: SingleAlert
version: 1.0.0
id: ddee1398-cf0b-46af-b583-78c3c29156dc
severity: Medium
kind: Scheduled
queryFrequency: 10m
description: |
"This rule is designed to identify when the system is experiencing abnormal errors."
requiredDataConnectors:
- connectorId: DatawizaDapSolution
dataTypes:
- datawizaserveraccess_CL
triggerOperator: GreaterThan
name: Datawiza - massive errors detected
tactics:
- Discovery
alertDetailsOverride:
alertDescriptionFormat: |
Detected {{Count}} errors within 10 minutes. Please investigate unauthorized access attempts or misconfigurations.
alertDisplayNameFormat: Datawiza Massive Error Detection
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Datawiza/Analytic Rules/DatawizaSentinelAlerts.yaml
triggerThreshold: 0
queryPeriod: 10m
query: |
let timeFrame = 10m;
datawizaserveraccess_CL
| where TimeGenerated between (ago(timeFrame) .. now())
and Status_d >= 500
| summarize Count = count()
| where Count > 100