Back
Ide65938c4-1379-4f7a-bd22-78f670a239c3
RulenameGuardian- Language Detection Policy Violation Detection
DescriptionThis alert creates an incident when Language Detection Policy Violation detected from the Guardian.
SeverityInformational
Required data connectorsBoschAIShield
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/AIShield%20AI%20Security%20Monitoring/Analytic%20Rules/LanguageDetectionVulDetection.yaml
Version1.0.0
Arm templatee65938c4-1379-4f7a-bd22-78f670a239c3.json
Deploy To Azure
Guardian
| where PolicyViolatedControlFeature =~ 'Language Detection'
| where Severity =~ 'Informational'
query: |
  Guardian
  | where PolicyViolatedControlFeature =~ 'Language Detection'
  | where Severity =~ 'Informational'
version: 1.0.0
alertDetailsOverride:
  alertDisplayNameFormat: Guardian- Language Detection Policy Violation detection
  alertSeverityColumnName: Severity
  alertTacticsColumnName: 
  alertDescriptionFormat: |
    This query detects Language Detection Policy Violation detected from the Guardian generated at {{TimeGenerated}}.\n\nPlease check the source for more information and investigate further.
tactics: []
name: Guardian- Language Detection Policy Violation Detection
triggerThreshold: 0
requiredDataConnectors:
- connectorId: BoschAIShield
  dataTypes:
  - Guardian
queryFrequency: 1h
queryPeriod: 1h
status: Available
triggerOperator: gt
entityMappings:
- fieldMappings:
  - identifier: HostName
    columnName: HostName
  - identifier: NTDomain
    columnName: NTDomain
  entityType: Host
- fieldMappings:
  - identifier: Address
    columnName: SourceIP
  entityType: IP
eventGroupingSettings:
  aggregationKind: SingleAlert
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/AIShield%20AI%20Security%20Monitoring/Analytic%20Rules/LanguageDetectionVulDetection.yaml
id: e65938c4-1379-4f7a-bd22-78f670a239c3
severity: Informational
description: |
  'This alert creates an incident when Language Detection Policy Violation detected from the Guardian.'
kind: Scheduled
relevantTechniques: []
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/e65938c4-1379-4f7a-bd22-78f670a239c3')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/e65938c4-1379-4f7a-bd22-78f670a239c3')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "This query detects Language Detection Policy Violation detected from the Guardian generated at {{TimeGenerated}}.\\n\\nPlease check the source for more information and investigate further.\n",
          "alertDisplayNameFormat": "Guardian- Language Detection Policy Violation detection",
          "alertSeverityColumnName": "Severity",
          "alertTacticsColumnName": null
        },
        "alertRuleTemplateName": "e65938c4-1379-4f7a-bd22-78f670a239c3",
        "customDetails": null,
        "description": "'This alert creates an incident when Language Detection Policy Violation detected from the Guardian.'\n",
        "displayName": "Guardian- Language Detection Policy Violation Detection",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "HostName",
                "identifier": "HostName"
              },
              {
                "columnName": "NTDomain",
                "identifier": "NTDomain"
              }
            ]
          },
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "SourceIP",
                "identifier": "Address"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "SingleAlert"
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/AIShield%20AI%20Security%20Monitoring/Analytic%20Rules/LanguageDetectionVulDetection.yaml",
        "query": "Guardian\n| where PolicyViolatedControlFeature =~ 'Language Detection'\n| where Severity =~ 'Informational'\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Informational",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [],
        "techniques": [],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}