AzureActivity
| where OperationNameValue contains "Microsoft.SecurityInsights/dataConnectors/"
| where ActivityStatusValue == "Succeeded"
| project OperationNameValue, Caller, CallerIpAddress, ActivityStatusValue, ActivitySubstatusValue, ResourceGroup, Properties, ResourceId, TimeGenerated
| sort by TimeGenerated desc
| extend Account = Caller
severity: Medium
triggerOperator: gt
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/MaturityModelForEventLogManagementM2131/Analytic Rules/M2131DataConnectorAddedChangedRemoved.yaml
id: eeb11b6b-e626-4228-b74d-3e730dca8999
entityMappings:
- fieldMappings:
- identifier: ResourceId
columnName: ResourceId
entityType: AzureResource
kind: Scheduled
status: Available
tactics:
- Discovery
queryFrequency: 1d
requiredDataConnectors: []
relevantTechniques:
- T1082
version: 1.0.0
description: |
'This alert is designed to monitor data connector configurations. This alert is triggered when a data connector is added, updated, or deleted.'
triggerThreshold: 0
query: |
AzureActivity
| where OperationNameValue contains "Microsoft.SecurityInsights/dataConnectors/"
| where ActivityStatusValue == "Succeeded"
| project OperationNameValue, Caller, CallerIpAddress, ActivityStatusValue, ActivitySubstatusValue, ResourceGroup, Properties, ResourceId, TimeGenerated
| sort by TimeGenerated desc
| extend Account = Caller
queryPeriod: 14d
name: M2131_DataConnectorAddedChangedRemoved