Skip to content

Commit 8fc5f23

Browse files
authored
Merge pull request Azure#13186 from socprime/socprime_connector_24_11_25
socprime_connector_first_commit
2 parents 85655a3 + f1e081c commit 8fc5f23

12 files changed

Lines changed: 1110 additions & 0 deletions

Logos/SOCPrime_Logo.svg

Lines changed: 21 additions & 0 deletions
Loading
Lines changed: 64 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,64 @@
1+
{
2+
"name": "SOCPrimeLogsDCR",
3+
"apiVersion": "2021-09-01-preview",
4+
"type": "Microsoft.Insights/dataCollectionRules",
5+
"location": "{{location}}",
6+
"kind": null,
7+
"properties": {
8+
"streamDeclarations": {
9+
"Custom-SOCPrimeAuditLogsStreamAgent": {
10+
"columns": [
11+
{
12+
"name": "timestamp",
13+
"type": "datetime"
14+
},
15+
{
16+
"name": "event_name",
17+
"type": "string"
18+
},
19+
{
20+
"name": "user_email",
21+
"type": "string"
22+
},
23+
{
24+
"name": "user_name",
25+
"type": "string"
26+
},
27+
{
28+
"name": "event_page",
29+
"type": "string"
30+
},
31+
{
32+
"name": "source_ip",
33+
"type": "string"
34+
},
35+
{
36+
"name": "user_agent",
37+
"type": "string"
38+
}
39+
]
40+
}
41+
},
42+
"destinations": {
43+
"logAnalytics": [
44+
{
45+
"workspaceResourceId": "[variables('workspaceResourceId')]",
46+
"name": "clv2ws1"
47+
}
48+
]
49+
},
50+
"dataFlows": [
51+
{
52+
"streams": [
53+
"Custom-SOCPrimeAuditLogsStreamAgent"
54+
],
55+
"destinations": [
56+
"clv2ws1"
57+
],
58+
"transformKql": "source | extend EventType = 'event'| extend EventVendor = 'SOC Prime' | extend EventProduct = 'TDM Audit Logs'| project TimeGenerated = timestamp, EventName = event_name, UserName=user_name, HttpUserAgent = user_agent, Uri=event_page, UserEmail=user_email, SourceIp=source_ip",
59+
"outputStream": "Custom-SOCPrimeAuditLogs_CL"
60+
}
61+
],
62+
"dataCollectionEndpointId": "[concat('/subscriptions/',parameters('subscription'),'/resourceGroups/',parameters('resourceGroupName'),'/providers/Microsoft.Insights/dataCollectionEndpoints/',parameters('workspace'))]"
63+
}
64+
}

0 commit comments

Comments
 (0)