Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

M2131_DataConnectorAddedChangedRemoved

Back
Ideeb11b6b-e626-4228-b74d-3e730dca8999
RulenameM2131_DataConnectorAddedChangedRemoved
DescriptionThis alert is designed to monitor data connector configurations. This alert is triggered when a data connector is added, updated, or deleted.
SeverityMedium
TacticsDiscovery
TechniquesT1082
KindScheduled
Query frequency1d
Query period14d
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/MaturityModelForEventLogManagementM2131/Analytic Rules/M2131DataConnectorAddedChangedRemoved.yaml
Version1.0.0
Arm templateeeb11b6b-e626-4228-b74d-3e730dca8999.json
Deploy To Azure
AzureActivity
| where OperationNameValue contains "Microsoft.SecurityInsights/dataConnectors/"
| where ActivityStatusValue == "Succeeded"
| project OperationNameValue, Caller, CallerIpAddress, ActivityStatusValue, ActivitySubstatusValue, ResourceGroup, Properties, ResourceId, TimeGenerated
| sort by TimeGenerated desc
| extend Account = Caller
queryPeriod: 14d
query: |
  AzureActivity
  | where OperationNameValue contains "Microsoft.SecurityInsights/dataConnectors/"
  | where ActivityStatusValue == "Succeeded"
  | project OperationNameValue, Caller, CallerIpAddress, ActivityStatusValue, ActivitySubstatusValue, ResourceGroup, Properties, ResourceId, TimeGenerated
  | sort by TimeGenerated desc
  | extend Account = Caller  
name: M2131_DataConnectorAddedChangedRemoved
entityMappings:
- fieldMappings:
  - columnName: ResourceId
    identifier: ResourceId
  entityType: AzureResource
queryFrequency: 1d
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/MaturityModelForEventLogManagementM2131/Analytic Rules/M2131DataConnectorAddedChangedRemoved.yaml
requiredDataConnectors: []
description: |
    'This alert is designed to monitor data connector configurations. This alert is triggered when a data connector is added, updated, or deleted.'
kind: Scheduled
version: 1.0.0
status: Available
severity: Medium
relevantTechniques:
- T1082
triggerOperator: gt
triggerThreshold: 0
tactics:
- Discovery
id: eeb11b6b-e626-4228-b74d-3e730dca8999