From 95c5faa63a8ef77cde3516e2f7796d2d726f4754 Mon Sep 17 00:00:00 2001 From: v-sabiraj <94349919+v-sabiraj@users.noreply.github.com> Date: Fri, 31 Jul 2026 13:53:01 +0530 Subject: [PATCH] Upgrade Azure Storage solution to v3.0.0 Bumps the Azure Storage solution from v2.0.2 to v3.0.0: - Migrates from TemplateSpec to contentTemplates/contentPackages (ARM API 2023-04-01-preview) - Adds _solutionName, _solutionVersion, and content product ID variables - Updates createUiDefinition.json description and data connector text - Adds ReleaseNotes.md, testParameters.json, and 3.0.0.zip package - Updates BasePath in Solution_AzureStorage.json --- .../Data/Solution_AzureStorage.json | 6 +- Solutions/Azure Storage/Package/3.0.0.zip | Bin 0 -> 6683 bytes .../Package/createUiDefinition.json | 8 +- .../Azure Storage/Package/mainTemplate.json | 71 +++++++++--------- .../Azure Storage/Package/testParameters.json | 24 ++++++ Solutions/Azure Storage/ReleaseNotes.md | 3 + 6 files changed, 71 insertions(+), 41 deletions(-) create mode 100644 Solutions/Azure Storage/Package/3.0.0.zip create mode 100644 Solutions/Azure Storage/Package/testParameters.json create mode 100644 Solutions/Azure Storage/ReleaseNotes.md diff --git a/Solutions/Azure Storage/Data/Solution_AzureStorage.json b/Solutions/Azure Storage/Data/Solution_AzureStorage.json index d1c12ac3ce6..fe0e153f715 100644 --- a/Solutions/Azure Storage/Data/Solution_AzureStorage.json +++ b/Solutions/Azure Storage/Data/Solution_AzureStorage.json @@ -6,9 +6,9 @@ "Data Connectors": [ "Solutions/Azure Storage/Data Connectors/AzureStorageAccount_CCP.json" ], - "BasePath": "C:\\Sentinel-Repos\\19.05.22\\Azure-Sentinel", - "Version": "2.0.2", + "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Azure Storage", + "Version": "3.0.0", "Metadata": "SolutionMetadata.json", - "TemplateSpec": true, + "TemplateSpec": false, "Is1PConnector": false } \ No newline at end of file diff --git a/Solutions/Azure Storage/Package/3.0.0.zip b/Solutions/Azure Storage/Package/3.0.0.zip new file mode 100644 index 0000000000000000000000000000000000000000..8bf90c84a2dcd027ff26bf95070d126a8d6ba3af GIT binary patch literal 6683 zcmZ{JRa6|nvMuiJI=H(#1Sb&OAwYsVgAW=cFt|HGf(F;%?(Xh3cm|iCH~0L!_wHM_ z`=hIBRn@A$UA?!43OoV<3=9kk488OF=gb7gg*+q}m;yW)7~+3X3pcB;9#*<`a#q%M z&UPMlF3z0x?k>*14V+xoM{wT&)bC$=nrfMqiYW7srERN$`~7z?rI>izlvqhpl_R*n z@7%!6e2oP~NKeL3^G_;KCS4JYmS)hPKpr{hd57f9#7v%97feLp^eT}GAqVwZlun1z z{GqBAYXutnta5?mB35$D*nQ0W%>k{CKn=x~!$z?S1#9m`cY9xKlM(;wfs>Qmy9VRC zWqo(Fb?=hi>PG%e)7I$(?z}?Mc)nl$Pr@$6;jBtx0I5Sf8$>5EB(4zA|GoyMAm&_w z7)%V4ct~}}1i7|_CAT86c^x&Xn?h>tAEyv;Z%bOb&hs>cX+OU!pN`XRFPf>ZS{5iA zABmbym{yG_`YZMxq}M2)oEC*>;;V}2`XoJ42FKM9W6y@VOn( z*HM$$_$05}bTu_c?OiP-`h;MMR3~N!7>f1%LlX))Z@AYQQSA_>2!fMg3eQ`tlnw81 zY+G2<CMi@#RvRdLu4}B=ZOOdx zolH9>t*ZsH%!_~}lyNZ?G4!lfKwCakN6T%jYIMp9Yc3XuK`5%Z7M>qq$}f8~g;BoW zm^!?w+@UXI{M`yjWppGha3?C9qCNC+Rd(fwu~BKvsf9F^VHN7S#hNiMA)5EM#T!%b zAm0V)xE{@RagDk^*ZzVlT2{C3V>5|c6`BgWs0FtUw=LU2O|DKSo%e9+7!au(Ud>^s z&~QD=UeJ$u)Sd>J6+fWH3VZDdJ$5UBKbvOy!zzUv!32V`l}Ab0;cPK5`18-ow<0(Z z1ZuU??RAQrRX=2`z^yM$zb${wjA-y3MxXHKLx$2D!4<#6EHx4=!UPqw|MYfK{tm^^ z5eVc>MQOZpivhQ95!kO5oF)9?VBZ$_&e!ubzua}RwVKr}iHtqvqj6l;b2B5bl-FHa z-;E4D8V|uu;|U8H{FxlpaPsCu)>u#zq8myAg+>@B{U_3qh_Gxdq*M=-fc2$g3Eo9c z*%r|cyXZS)Z&T|sr6WK4Q+98Ieu)%DG$Df1a@1;4m_f2j=8Oj`?sH*MhNgvXM9SNm z_Nu>s1Z`<5B0rlL4_|T#FU@I>-K6`ejj%*#CpcC^p{p^yA)X#BR}0Jyn|N!Xb3pj=anOe^Y|VUo~th zX)%y09pE?sJ)7+xrdXtu$zg}k@F ze!`{bT2l#Es1J^`|5OR2nyFkyY8QF?er6)w?Wv=$_=eo|d{}55e{2i8clxscYV%yE z?Y~0cYm1?eRH1yKtCRoP>}>_id#ik}izAX!4EA(885>vbreTYlcqB?}ot2DY25u{m zcVG1Qej6bPbxehM$`DU|Jh->SNrH(%;_LM<5~EuO#w~ZT_uWGnk(_AON0}p&g|Bdj z8g3rFiu!h^1?qpmji$YH5e7U@PLgD57F&|DTU+umB!6{R+mkzLXpk22w}XF`*Y(|k zM%S3-bc^QYeG`!C7LIl))LzVy&>!3+Cc0G3xExI_JdN`5qIX&#izSwd4Ilf3(QJ8b zP56d$3U5DyH2ss>TL%)TvSw$|^VpUw0I!6B)7y=Q$F63_=HKSZ{VttJ_G;J2t}9>% zBVxB^;U?%D)F9mYu*YW$F$cYRu5hO`iQ~4FP`2H(&-#dmLN`CY3|?U{8r5R>vO-9h zIHIN`YqEaS6b!P8W(O0aH(LXnqO2>JL2ggCyXm(&;MZGHKD6=fU>-8yFRI(+o-vO5oK=Oh?!=W|Ua5T(XuJACS;oG%Ms z7B#%QJ;G$>sidnkkDNS$F7zQ@nhz=9oz0M~np%bUrhSCK0y18!{&P~UDZ@z_D-s!L z)#gIUW_BiEE3SunfbnDp7r6kdrBWkp(+hfk zHym=kv#8htL7b~#@Or6Hj(yoFPXGXE%)eGoemvHTJ$ZYiVC*pWIgl-R>hj2l6zYt? zdOq<0^);f8bfn=Re$ymMYD3^}jv}iI89`4&MW}0dYv2 zm=b|t2xl3UuiWgL6g~D^|LF-91%R3CSGOh&DRyn1=C_FV!R}`r+;rxm9esb8FNsQ% ztvv-b8FVcN+K7T9%owd2->#EwloIUZy!Yu)@f=KmTv{>6`Q{;C#t_978Fyq{rL7nG z?DH@YX>bQhqtG&c_U>c#3KGS`uzM0~oqu5M4KbV(;_VG_C!1K<@I@;ev`AO`cu>}j z%Qbhmh05wfPw^DGquJ6qukP!U=j0$y?P@%S%N}D_Z|aViSmcb&m>3eImEM*w{9R6& zy01C44N1N@ByW0O?L1l}UVJ%lGWC`6_xq>sXTbC}sR!6MwO~Xo%{}vq{6m7kF36ry z_`pvunZs$In9USL20}WTm#j$!8uV=MXqu)fzc@N?`VgDW7RKTCsP(l8k)?xcr#ol| z=Xd8_+Ek-8klPoXS2NAhk$y!`Dat4~EA)k7AfyQ3d0A7nCF9W4oV4BS<+ZhZlWWl$ z(%|OgFmSz{{6{a!1y;~pQ_OJ`@o_3I5~$ZH+`+xo^iiGguD&ykfUTI?E+kNgzX#Tbe0?#qJtt!&v%NF*)Z~3Q z0nJHrKn$Hedoq=xXo$AiH$mX{Ex0Nt2ViN`ny*Hm(Wa6;q8T=6nZasdN)D|1ek!NU zkW9~Q`h7v#31DTSh3ef|C5`BA+}XC)bhcvL$^4~TZUL0=#~N-VidvsluvU|-Uxl7f z@kJ=4Ju$gl=Ti;sGQXnIlBF-QY>|IOGep$*37Z?^GYQh3pmN1oIafnth8`J@^Aj8S z*7v^*u*I)je4R+sbH>?6mO~9=Q03Jhr0jpEGFoG@)k6#J{w+hf`u(2T+JNsN+uZ4B zA`yeBB;gZsLU{EtY*g68e%1wc;E*kD-)xqs;Ho)heGD#(g1;Yg@2Y2#=6sa93RGmt zTCRt`&=9@8JUsYD0`QKqCOpKf))F$yJIsJYXaKFB27hLbaOUkzVuQ>g%BpIOtwq1!7(tR&2oY}HjnpBdib^-3fx-3YC|%9v zLo_7^-PiCS!hMR>{!W?wPZb;eDhIM4>Gd-*;98FWdSk^~Fp>`UQE5X6uN7mWF175Q z`V~f13q{bNo^{MBsu@kBLii`23imGtS@Rt8l&a#4NBrGMoGd?hF7)L-x4$&?OzdZJ zbK;-~1L8LZuThtYCB4f~VuT`?rl~2(aC%$L`!i*zexjh$<4lK&0Z_Fw)Ze5j8S?rD z_VHIkS#Exv_j2LJUYZq$EyClq?C|<UxTQ9mz;KFcVy~v zA9`+utbFl3tK0F#!Foe}w}LiYfy5~Ql7BCZ7awx4Cj!#gqZ{Lutp2zu21W!NA~Rh| z3MVOn|J%X=(($9u9Q>GoSS9`-3T+hVmQe6RW{qLrR zb}^IRuBCUzBWcolya9PXZZaKNLm>9?NoCyy%?6y zBhopb3TKMuj)I7kObW3fcwLb~S}IR-R#3=HO^Bm$cW{h<9?E@WpGe~AkLj(UA(-hN zCaPxlzD>jG91PoVSy0nl(rgHwcj*sT=DD(ARohcq^gw<@O`wz0NQ&gV1*$ z%Rcdvgj>8T11)uS_rF*w3>p6TE@+ZrELZd#toq`tdP-r_^iaMu$2Q2l8a|b=zy%wn zbwhvpf=h?0A!#h%LANFE?Fi*mPn}ON3sDQMM>M|02mt~uGs=_70D`BApmy4E?7Ets zE31>sTKTK*1wyI{^wotv4Y?tBxK*~s&1xG8h$g4Ajg!|&VNs@6vUQj{WQ<8s z&u%8M%AbeHp**GLo%L-|2hFgA)Gdm^N~6}WjH^J{6k&H1PxmYAmQiGD{&ly_K0McV zEjiH>h|DYyA01NMxvr$Op`NA#n>QrZY~&oHyy3v`^>`Du_xEq7CT~}|rP=nw#5xTV z3<~JriO7nE_5Nb9cDNgT8&wL4bLC!I^_Ki(E%R5II}5D1e2{NglRYy^1HTVII1xt} z!N8o1gntX8>l7(L^ zRBRU%{JT+t-ayN>pSu@z`p7_I3wb4ouMu!uri|?|vE*+KbJp)rZL9upnk+^QFuJ0g z7{w&w6x%gGr=*ve_GrQfOZ|_%_t|k+WeJ|mx$%}-? z!wCqSp4q9+&hnV8#*!p$+(!U5WD4KQyH=SiC43K>fr=PdQcgHlvia=HAyu8@d}hLj4V`x_=@%+%E6JG> zNpE}u+3)grd8cc=B+<6F@1OzJK-I{A;6iBL+pm zam+qrnc!bzJZ8&SL_SvCiIH3{(2%-$=gOmxe~G*lZ`llSap|VSro*S(=#|Bgd`VBk z^SQ{5txZH5wH$|x%XrWS>!@y%6yAcU!On-nMsImK-Kk&uUMY*&%IrvbeU~JOBA_3jcal`Cn zqjHu}^Q_5!z09t#KJfPe5&5!;v)NIAK1yZzD(6ZS6f~XbfjjNr7NK8m`mGU?W7^_PQ)7JK8QoFi zoaoK(3ht-bYg*_t&xf&0^LmsLb+zTdKOjKUH0S(5I?SG4`!xZ!{C~ITH&LvIo9)5RjYC>mTC3{Gw<> z>9hMXcF}|(kv4p6Fc^N~gn7L~<5ZmiM$n!#H%P1j7%>eS`KN*iKb3V9?}aC|zqHb@ zvirDG{Q|dO(n064-%xo_c~wRs$N6aM<+a0bA`s0|w93|qHv-FxW#zt8AUs-K2S%Sh zy198zt(HB3L%4aZj6lZ@?ZFU|^6Ac>2a1u1pA6rOyW*bB2O0z@9PS;4cx;NT!;m&0 zT!gG?DJ-x8hKO%IW;$XY*|{pCq|z2D7H1uER^GVy164>P))mC%=X%UeDZ(I!_-789 zLX|R)rCMnEIQ40$Ru4}3RbVz)jt!Khd3$j)^!*dup$j*PU#BH#iRnv7g{)zYPY>Dr z8{3ErYIsmS5#~&Sg-=LXpWxPz-#-s9W8Hg7cliLPJ@xP=&O$)hJDqAX&VWj(W#9g7 zbZ`aY+mh^#bJay5E3j$oRiC3;kL`1%0?2?8OAj3S+mND??4@EcCs{zlYi;kd1Vxwb z>(I>WN<|p8ZK&~GSVUD1hHaSQUD!xf%fU99%_(}KaUfeaW}r^sW+wsO7>(i>uIRdS zj6Yt8r*nTHMT)T$*<%9{r4*?41KemGzsJLahw6@0xD==jQ^IYO6(XB z&a8El_N)~m>-oI|*~e2U{c(l=)#>8=EbuF>LU5a8@S07orV>v_U`kV@OH-hF7O%~Z zAx@L-rJ!$q2XmKD0!MAu=ur;SHF9kScX1zQaSwZO7i%%+h{MKDXBUky)|?%l`4-<+lW@TZqSXnm>@3W{}$LZeF#KUg=|FCE%YX5}NwTkauO=508$VG*2ijO=(xF!*x5u90o*?-JqnE^(b ze+8QV$pT~GR$VFmrENrDu+1%2DkN zoBR0kqNvw|BwyaXzy0L`RUmWd!>FN5Am&K6E7v$rWn?MhcZ7({TywuSgZtLU8!gvcMtU&fI^#fl4CnYx-Lu&ORw->>sftxsY^xHI6d2FySnUU&?9J4W1SN})(jNZ1Gk>ejxMi$Akurr*$xU9K6v zWt|1t){PqAJz8@E=*^tWDIzCbfTjvAHI?%nrIF~iPx$7ZLk7L7A8wL(lJ$dJgm`cI z`|d3x&&mU`HL;UPW9kPt^8@Or_Y!ZRJx8$p%|j>6F+84NJEV-){PoF>8_aoz&*d|n zPY7lkLv)!HMQlJGI@sqTRco5R1H6HK#G*dlN@F2=DyI|h&?{0#1G%I&^z~5;%4GB$ z{R5-!-Kl)UnI3whgFnhvMgjvW(D}zI*CftU^O}@05yHs(dfJLP(Yhk0tInffMVkTg z0m;RoQo!IRxV_aVG&8K~%6Z{IT?fRHKCK-%|J&0Hd^{iJ@lDS=`tKlDugJi=T$nBt z#2sLnGs?G`53J}k>ury9XjFid$R>5iALFEGRUn~L%>)oER)SPSAolH5G}a~ z+r~7JxE(Q`h6Nr9QKWM5>)9jo7?O`8%F;R%;V+APZmCzBX2FGhv^}#7xq$yH0LyW< zoo|?2rs&qHz2JY!LY!NJhE~j4of?`&FUL;o2xBwXQf^^>f_h^^9hQt6P2C)TFHZXr zUn%8U7!RD_F1hcP&`qv`f zpYjVP#TK4K6aH<+Axvi$BY>7KXG(pDDAzxXVP8Z*2YmN(H(nf=^T?^6OmP-&YfBzt zW=szJWxJ_G+romc)yadupDxD)*(dwzh>d+dE9_!7YHneul}TeFKE;_*DSv-3w$rk~ zRLP7z>$`h35_U^A>^Aql3fW5\n\n**Note:** _There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing._\n\nThe [Azure Storage account](https://docs.microsoft.com/azure/storage/common/storage-account-overview) Solution for Microsoft Sentinel enables you to stream Azure Storage accounts diagnostics logs into your Microsoft Sentinel workspace, allowing you to continuously monitor activity in all your instances, and detect malicious activity in your organization. \n\n**Underlying Microsoft Technologies used:**\n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n\n a. [Azure Monitor Resource Diagnostics](https://docs.microsoft.com/azure/azure-monitor/essentials/diagnostic-settings)\n\n**Data Connectors:** 1\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", + "description": "\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Azure%20Storage/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe [Azure Storage account](https://docs.microsoft.com/azure/storage/common/storage-account-overview) Solution for Microsoft Sentinel enables you to stream Azure Storage accounts diagnostics logs into your Microsoft Sentinel workspace, allowing you to continuously monitor activity in all your instances, and detect malicious activity in your organization. \n\n**Underlying Microsoft Technologies used:**\n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n\n a. [Azure Monitor Resource Diagnostics](https://docs.microsoft.com/azure/azure-monitor/essentials/diagnostic-settings)\n\n**Data Connectors:** 1\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", "subscription": { "resourceProviders": [ "Microsoft.OperationsManagement/solutions", @@ -60,11 +60,11 @@ "name": "dataconnectors1-text", "type": "Microsoft.Common.TextBlock", "options": { - "text": "This solution installs the data connector for ingesting Azure Storage accounts diagnostics logs into Microsoft Sentinel. After installing the solution, configure and enable this data connector by following guidance in Manage solution view." + "text": "This Solution installs the data connector for Azure Storage. You can get Azure Storage custom log data in your Microsoft Sentinel workspace. After installing the solution, configure and enable this data connector by following guidance in Manage solution view." } }, { - "name": "dataconnectors-link2", + "name": "dataconnectors-link1", "type": "Microsoft.Common.TextBlock", "options": { "link": { @@ -82,4 +82,4 @@ "workspace": "[basics('workspace')]" } } -} \ No newline at end of file +} diff --git a/Solutions/Azure Storage/Package/mainTemplate.json b/Solutions/Azure Storage/Package/mainTemplate.json index 475ffaa9f64..a86fd90dd53 100644 --- a/Solutions/Azure Storage/Package/mainTemplate.json +++ b/Solutions/Azure Storage/Package/mainTemplate.json @@ -30,49 +30,34 @@ } }, "variables": { - "solutionId": "azuresentinel.azure-sentinel-solution-azurestorageaccount", - "_solutionId": "[variables('solutionId')]", "email": "support@microsoft.com", "_email": "[variables('email')]", - "workspaceResourceId": "[resourceId('microsoft.OperationalInsights/Workspaces', parameters('workspace'))]", + "_solutionName": "Azure Storage", + "_solutionVersion": "3.0.0", + "solutionId": "azuresentinel.azure-sentinel-solution-azurestorageaccount", + "_solutionId": "[variables('solutionId')]", "uiConfigId1": "AzureStorageAccount", "_uiConfigId1": "[variables('uiConfigId1')]", "dataConnectorContentId1": "AzureStorageAccount", "_dataConnectorContentId1": "[variables('dataConnectorContentId1')]", "dataConnectorId1": "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/dataConnectors', variables('_dataConnectorContentId1'))]", "_dataConnectorId1": "[variables('dataConnectorId1')]", - "dataConnectorTemplateSpecName1": "[concat(parameters('workspace'),'-dc-',uniquestring(variables('_dataConnectorContentId1')))]", - "dataConnectorVersion1": "1.0.0" + "dataConnectorTemplateSpecName1": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat(parameters('workspace'),'-dc-',uniquestring(variables('_dataConnectorContentId1'))))]", + "dataConnectorVersion1": "1.0.0", + "_dataConnectorcontentProductId1": "[concat(take(variables('_solutionId'),50),'-','dc','-', uniqueString(concat(variables('_solutionId'),'-','DataConnector','-',variables('_dataConnectorContentId1'),'-', variables('dataConnectorVersion1'))))]", + "_solutioncontentProductId": "[concat(take(variables('_solutionId'),50),'-','sl','-', uniqueString(concat(variables('_solutionId'),'-','Solution','-',variables('_solutionId'),'-', variables('_solutionVersion'))))]" }, "resources": [ { - "type": "Microsoft.Resources/templateSpecs", - "apiVersion": "2021-05-01", + "type": "Microsoft.OperationalInsights/workspaces/providers/contentTemplates", + "apiVersion": "2023-04-01-preview", "name": "[variables('dataConnectorTemplateSpecName1')]", "location": "[parameters('workspace-location')]", - "tags": { - "hidden-sentinelWorkspaceId": "[variables('workspaceResourceId')]", - "hidden-sentinelContentType": "DataConnector" - }, - "properties": { - "description": "Azure Storage data connector with template", - "displayName": "Azure Storage template" - } - }, - { - "type": "Microsoft.Resources/templateSpecs/versions", - "apiVersion": "2021-05-01", - "name": "[concat(variables('dataConnectorTemplateSpecName1'),'/',variables('dataConnectorVersion1'))]", - "location": "[parameters('workspace-location')]", - "tags": { - "hidden-sentinelWorkspaceId": "[variables('workspaceResourceId')]", - "hidden-sentinelContentType": "DataConnector" - }, "dependsOn": [ - "[resourceId('Microsoft.Resources/templateSpecs', variables('dataConnectorTemplateSpecName1'))]" + "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Azure Storage data connector with template version 2.0.2", + "description": "Azure Storage data connector with template version 3.0.0", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('dataConnectorVersion1')]", @@ -326,7 +311,7 @@ }, { "type": "Microsoft.OperationalInsights/workspaces/providers/metadata", - "apiVersion": "2022-01-01-preview", + "apiVersion": "2023-04-01-preview", "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat('DataConnector-', last(split(variables('_dataConnectorId1'),'/'))))]", "properties": { "parentId": "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/dataConnectors', variables('_dataConnectorContentId1'))]", @@ -351,12 +336,23 @@ } } ] - } + }, + "packageKind": "Solution", + "packageVersion": "[variables('_solutionVersion')]", + "packageName": "[variables('_solutionName')]", + "packageId": "[variables('_solutionId')]", + "contentSchemaVersion": "3.0.0", + "contentId": "[variables('_dataConnectorContentId1')]", + "contentKind": "DataConnector", + "displayName": "Azure Storage Account", + "contentProductId": "[variables('_dataConnectorcontentProductId1')]", + "id": "[variables('_dataConnectorcontentProductId1')]", + "version": "[variables('dataConnectorVersion1')]" } }, { "type": "Microsoft.OperationalInsights/workspaces/providers/metadata", - "apiVersion": "2022-01-01-preview", + "apiVersion": "2023-04-01-preview", "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat('DataConnector-', last(split(variables('_dataConnectorId1'),'/'))))]", "dependsOn": [ "[variables('_dataConnectorId1')]" @@ -630,13 +626,20 @@ } }, { - "type": "Microsoft.OperationalInsights/workspaces/providers/metadata", - "apiVersion": "2022-01-01-preview", + "type": "Microsoft.OperationalInsights/workspaces/providers/contentPackages", + "apiVersion": "2023-04-01-preview", "location": "[parameters('workspace-location')]", "properties": { - "version": "2.0.2", + "version": "3.0.0", "kind": "Solution", - "contentSchemaVersion": "2.0.0", + "contentSchemaVersion": "3.0.0", + "displayName": "Azure Storage", + "publisherDisplayName": "Microsoft Sentinel, Microsoft Corporation", + "descriptionHtml": "

Note: Please refer to the following before installing the solution:

\n

• Review the solution Release Notes

\n

• There may be known issues pertaining to this Solution, please refer to them before installing.

\n

The Azure Storage account Solution for Microsoft Sentinel enables you to stream Azure Storage accounts diagnostics logs into your Microsoft Sentinel workspace, allowing you to continuously monitor activity in all your instances, and detect malicious activity in your organization.

\n

Underlying Microsoft Technologies used:

\n

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

\n
    \n
  1. Azure Monitor Resource Diagnostics
  2. \n
\n

Data Connectors: 1

\n

Learn more about Microsoft Sentinel | Learn more about Solutions

\n", + "contentKind": "Solution", + "contentProductId": "[variables('_solutioncontentProductId')]", + "id": "[variables('_solutioncontentProductId')]", + "icon": "", "contentId": "[variables('_solutionId')]", "parentId": "[variables('_solutionId')]", "source": { diff --git a/Solutions/Azure Storage/Package/testParameters.json b/Solutions/Azure Storage/Package/testParameters.json new file mode 100644 index 00000000000..e55ec41a9ac --- /dev/null +++ b/Solutions/Azure Storage/Package/testParameters.json @@ -0,0 +1,24 @@ +{ + "location": { + "type": "string", + "minLength": 1, + "defaultValue": "[resourceGroup().location]", + "metadata": { + "description": "Not used, but needed to pass arm-ttk test `Location-Should-Not-Be-Hardcoded`. We instead use the `workspace-location` which is derived from the LA workspace" + } + }, + "workspace-location": { + "type": "string", + "defaultValue": "", + "metadata": { + "description": "[concat('Region to deploy solution resources -- separate from location selection',parameters('location'))]" + } + }, + "workspace": { + "defaultValue": "", + "type": "string", + "metadata": { + "description": "Workspace name for Log Analytics where Microsoft Sentinel is setup" + } + } +} diff --git a/Solutions/Azure Storage/ReleaseNotes.md b/Solutions/Azure Storage/ReleaseNotes.md new file mode 100644 index 00000000000..33f9654306b --- /dev/null +++ b/Solutions/Azure Storage/ReleaseNotes.md @@ -0,0 +1,3 @@ +| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** | +|-------------|--------------------------------|--------------------------------------------------------------------------| +| 3.0.0 | 31-07-2026 | Updated Solution to version 3.0.0 by migrating from TemplateSpec to contentTemplates/contentPackages | \ No newline at end of file