TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0034" and (priority_s == "P1" or priority_s == "P2")
queryFrequency: 5m
entityMappings:
severity: High
triggerThreshold: 0
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Theom/Analytic Rules/TRIS0034_Overprovisioned_Roles_Shadow_DB.yaml
query: |
TheomAlerts_CL
| where customProps_RuleId_s == "TRIS0034" and (priority_s == "P1" or priority_s == "P2")
id: fb7769d0-e622-4479-95b4-f6266a5b41e2
triggerOperator: gt
version: 1.0.0
requiredDataConnectors:
- connectorId: Theom
dataTypes:
- TheomAlerts_CL
eventGroupingSettings:
aggregationKind: AlertPerResult
description: |
"Creates Sentinel incidents for critical/high Theom risks, associated with ruleId TRIS0034 (Theom has observed shadow (or clone) databases/tables. Additionally, it has observed roles that are overprovisioned for these data stores. As per this requirement, use this information to apply data access control lists or access permissions and enforce data retention policies)"
alertDetailsOverride:
alertDescriptionFormat: |2
Summary: {{summary_s}}
Additional info: {{details_s}}
Please investigate further on Theom UI at {{deepLink_s}}
alertDisplayNameFormat: 'Theom Alert ID: {{id_s}} '
status: Available
name: Theom - Overprovisioned Roles Shadow DB
queryPeriod: 5m
kind: Scheduled
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspace": {
"type": "String"
}
},
"resources": [
{
"id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/fb7769d0-e622-4479-95b4-f6266a5b41e2')]",
"name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/fb7769d0-e622-4479-95b4-f6266a5b41e2')]",
"type": "Microsoft.OperationalInsights/workspaces/providers/alertRules",
"kind": "Scheduled",
"apiVersion": "2022-11-01",
"properties": {
"displayName": "Theom - Overprovisioned Roles Shadow DB",
"description": "\"Creates Sentinel incidents for critical/high Theom risks, associated with ruleId TRIS0034 (Theom has observed shadow (or clone) databases/tables. Additionally, it has observed roles that are overprovisioned for these data stores. As per this requirement, use this information to apply data access control lists or access permissions and enforce data retention policies)\"\n",
"severity": "High",
"enabled": true,
"query": "TheomAlerts_CL\n | where customProps_RuleId_s == \"TRIS0034\" and (priority_s == \"P1\" or priority_s == \"P2\")\n",
"queryFrequency": "PT5M",
"queryPeriod": "PT5M",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0,
"suppressionDuration": "PT1H",
"suppressionEnabled": false,
"alertRuleTemplateName": "fb7769d0-e622-4479-95b4-f6266a5b41e2",
"eventGroupingSettings": {
"aggregationKind": "AlertPerResult"
},
"alertDetailsOverride": {
"alertDescriptionFormat": "\nSummary: {{summary_s}} \nAdditional info: {{details_s}}\nPlease investigate further on Theom UI at {{deepLink_s}}\n",
"alertDisplayNameFormat": "Theom Alert ID: {{id_s}} "
},
"customDetails": null,
"entityMappings": null,
"templateVersion": "1.0.0",
"status": "Available",
"OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Theom/Analytic Rules/TRIS0034_Overprovisioned_Roles_Shadow_DB.yaml"
}
}
]
}