Skip to content

Commit 4b688e2

Browse files
author
Charles Zhao (赵灿)
committed
Remove deprecated CitrixAnalytics_CCC_Events_V1_CL table and add workbook preview images
- Delete CitrixAnalytics_tableCCCEvents.json (table removed) - Remove CCC stream declaration and dataFlow from CitrixAnalytics_DCR.json - Remove CCC count from workbook KQL query - Add 6 workbook preview images (Black/White x3) to Workbooks/Images/Preview/ - Regenerate Package (mainTemplate.json, createUiDefinition.json, 3.0.0.zip) with CCC removed
1 parent cbf114c commit 4b688e2

12 files changed

Lines changed: 40 additions & 217 deletions

Solutions/Citrix Analytics CCF/Data Connectors/CitrixAnalytics_CCF/CitrixAnalytics_DCR.json

Lines changed: 0 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -106,25 +106,6 @@
106106
{ "name": "indicator_category_id", "type": "int" }
107107
]
108108
},
109-
"Custom-CitrixAnalytics_CCC_Events_V1": {
110-
"columns": [
111-
{ "name": "account_id", "type": "string" },
112-
{ "name": "client_ip", "type": "string" },
113-
{ "name": "client_os", "type": "string" },
114-
{ "name": "entity_id", "type": "string" },
115-
{ "name": "entity_type", "type": "string" },
116-
{ "name": "event_id", "type": "string" },
117-
{ "name": "event_type", "type": "string" },
118-
{ "name": "event_user_id", "type": "string" },
119-
{ "name": "oauth_client_id", "type": "string" },
120-
{ "name": "occurrence_event_type", "type": "string" },
121-
{ "name": "operation_name", "type": "string" },
122-
{ "name": "product", "type": "string" },
123-
{ "name": "tenant_id", "type": "string" },
124-
{ "name": "timestamp", "type": "datetime" },
125-
{ "name": "version", "type": "int" }
126-
]
127-
},
128109
"Custom-CitrixAnalytics_CVAD_Events_V1": {
129110
"columns": [
130111
{ "name": "event_type", "type": "string" },
@@ -255,16 +236,6 @@
255236
"transformKql": "source | where event_type=='indicatorSummary' | extend TimeGenerated = todatetime(timestamp)",
256237
"outputStream": "Custom-CitrixAnalytics_indicatorSummary_V1_CL"
257238
},
258-
{
259-
"streams": [
260-
"Custom-CitrixAnalytics_CCC_Events_V1"
261-
],
262-
"destinations": [
263-
"clv2ws1"
264-
],
265-
"transformKql": "source | where event_type=='datasourceCCCEventDetails' | extend TimeGenerated = todatetime(timestamp)",
266-
"outputStream": "Custom-CitrixAnalytics_CCC_Events_V1_CL"
267-
},
268239
{
269240
"streams": [
270241
"Custom-CitrixAnalytics_CVAD_Events_V1"

Solutions/Citrix Analytics CCF/Data Connectors/CitrixAnalytics_CCF/CitrixAnalytics_tableCCCEvents.json

Lines changed: 0 additions & 29 deletions
This file was deleted.
10 Bytes
Binary file not shown.

Solutions/Citrix Analytics CCF/Package/createUiDefinition.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
"config": {
77
"isWizard": false,
88
"basics": {
9-
"description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/citrix-logo-circle-black.svg\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Citrix%20Analytics%20CCF/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\n[Citrix Analytics](https://www.citrix.com/solutions/analytics/) Solution for Microsoft Sentinel helps you to export data analyzed for the events(SPA, Security) from Citrix Analytics into Microsoft Sentinel environment. You can create custom dashboards, analyze data from other sources along with that from Citrix Analytics and create custom workflows using Logic Apps to monitor and mitigate the events. \nFor more details about this solution refer to https://docs.citrix.com/en-us/security-analytics/siem-integration/azure-sentinel-integration.html \n\n**Underlying Microsoft Technologies used:**\n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n a.[Azure Monitor HTTP Logs Ingestion API](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview)\n\n**Data Connectors:** 1, **Workbooks:** 1\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)",
9+
"description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/citrix_logo.svg\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Citrix%20Analytics%20CCF/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\n[Citrix Analytics](https://www.citrix.com/solutions/analytics/) Solution for Microsoft Sentinel helps you to export data analyzed for the events(SPA, Security) from Citrix Analytics into Microsoft Sentinel environment. You can create custom dashboards, analyze data from other sources along with that from Citrix Analytics and create custom workflows using Logic Apps to monitor and mitigate the events. \nFor more details about this solution refer to https://docs.citrix.com/en-us/security-analytics/siem-integration/azure-sentinel-integration.html \n\n**Underlying Microsoft Technologies used:**\n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n a.[Azure Monitor HTTP Logs Ingestion API](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview)\n\n**Data Connectors:** 1, **Workbooks:** 1\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)",
1010
"subscription": {
1111
"resourceProviders": [
1212
"Microsoft.OperationsManagement/solutions",

Solutions/Citrix Analytics CCF/Package/mainTemplate.json

Lines changed: 38 additions & 157 deletions
Large diffs are not rendered by default.

Solutions/Citrix Analytics CCF/Workbooks/CitrixAnalytics.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -128,7 +128,7 @@
128128
"type": 3,
129129
"content": {
130130
"version": "KqlItem/1.0",
131-
"query": "let spaCount = CitrixAnalytics_SPA_Events_V1_CL | count; \nlet userProfileCount = CitrixAnalytics_userProfile_V1_CL | count; \nlet indicatorEventDetailCount = CitrixAnalytics_indicatorEventDetails_V1_CL | count; \nlet indicatorSummaryCount = CitrixAnalytics_indicatorSummary_V1_CL | count ;\nlet riskScoreChangeCount = CitrixAnalytics_riskScoreChange_V1_CL | count ;\nlet cccCount = CitrixAnalytics_CCC_Events_V1_CL | count ;\nlet cvadCount = CitrixAnalytics_CVAD_Events_V1_CL | count ;\nprint toscalar(spaCount)\n +toscalar(userProfileCount)\n +toscalar(indicatorEventDetailCount)\n +toscalar(indicatorSummaryCount)\n +toscalar(riskScoreChangeCount)\n +toscalar(cccCount)\n +toscalar(cvadCount);",
131+
"query": "let spaCount = CitrixAnalytics_SPA_Events_V1_CL | count; \nlet userProfileCount = CitrixAnalytics_userProfile_V1_CL | count; \nlet indicatorEventDetailCount = CitrixAnalytics_indicatorEventDetails_V1_CL | count; \nlet indicatorSummaryCount = CitrixAnalytics_indicatorSummary_V1_CL | count ;\nlet riskScoreChangeCount = CitrixAnalytics_riskScoreChange_V1_CL | count ;\nlet cvadCount = CitrixAnalytics_CVAD_Events_V1_CL | count ;\nprint toscalar(spaCount)\n +toscalar(userProfileCount)\n +toscalar(indicatorEventDetailCount)\n +toscalar(indicatorSummaryCount)\n +toscalar(riskScoreChangeCount)\n +toscalar(cvadCount);",
132132
"size": 4,
133133
"title": "# Received Events",
134134
"timeContextFromParameter": "timeRange",
81.6 KB
Loading
105 KB
Loading
48.8 KB
Loading
80.5 KB
Loading

0 commit comments

Comments
 (0)