From f55ebb6d4f9579341f592e34c2f68b2fce018ded Mon Sep 17 00:00:00 2001 From: v-sabiraj Date: Wed, 12 Jun 2024 14:08:40 +0530 Subject: [PATCH] Updated link --- .../Data/Solution_PaloAltoCDL.json | 2 +- .../Data/system_generated_metadata.json | 4 ++-- Solutions/PaloAltoCDL/Package/3.0.1.zip | Bin 21567 -> 21558 bytes .../Package/createUiDefinition.json | 4 ++-- .../PaloAltoCDL/Package/mainTemplate.json | 14 +++++--------- 5 files changed, 10 insertions(+), 14 deletions(-) diff --git a/Solutions/PaloAltoCDL/Data/Solution_PaloAltoCDL.json b/Solutions/PaloAltoCDL/Data/Solution_PaloAltoCDL.json index 96d95b8e65..856d6261d6 100644 --- a/Solutions/PaloAltoCDL/Data/Solution_PaloAltoCDL.json +++ b/Solutions/PaloAltoCDL/Data/Solution_PaloAltoCDL.json @@ -2,7 +2,7 @@ "Name": "PaloAltoCDL", "Author": "Microsoft - support@microsoft.com", "Logo": "", - "Description": "The [Palo Alto Networks CDL](https://www.paloaltonetworks.com/cortex/cortex-data-lake) solution provides the capability to ingest [CDL logs](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/log-forwarding-schema-reference/log-forwarding-schema-overview) into Microsoft Sentinel.\n\r\n1. **PaloAltoCDL via AMA** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. **PaloAltoCDL via Legacy Agent** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of PaloAltoCDL via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).", + "Description": "The [Palo Alto Networks CDL](https://www.paloaltonetworks.com/cortex/cortex-data-lake) solution provides the capability to ingest [CDL logs](https://docs.paloaltonetworks.com/strata-logging-service/log-reference/log-forwarding-schema-overview) into Microsoft Sentinel.\n\r\n1. **PaloAltoCDL via AMA** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. **PaloAltoCDL via Legacy Agent** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of PaloAltoCDL via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).", "Workbooks": [ "Workbooks/PaloAltoCDL.json" ], diff --git a/Solutions/PaloAltoCDL/Data/system_generated_metadata.json b/Solutions/PaloAltoCDL/Data/system_generated_metadata.json index 2fef117cbb..b195fa3b31 100644 --- a/Solutions/PaloAltoCDL/Data/system_generated_metadata.json +++ b/Solutions/PaloAltoCDL/Data/system_generated_metadata.json @@ -2,7 +2,7 @@ "Name": "PaloAltoCDL", "Author": "Microsoft - support@microsoft.com", "Logo": "", - "Description": "The [Palo Alto Networks CDL](https://www.paloaltonetworks.com/cortex/cortex-data-lake) solution provides the capability to ingest [CDL logs](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/log-forwarding-schema-reference/log-forwarding-schema-overview) into Microsoft Sentinel.\n\r\n1. **PaloAltoCDL via AMA** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. **PaloAltoCDL via Legacy Agent** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of PaloAltoCDL via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).", + "Description": "The [Palo Alto Networks CDL](https://www.paloaltonetworks.com/cortex/cortex-data-lake) solution provides the capability to ingest [CDL logs](https://docs.paloaltonetworks.com/strata-logging-service/log-reference/log-forwarding-schema-overview) into Microsoft Sentinel.\n\r\n1. **PaloAltoCDL via AMA** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. **PaloAltoCDL via Legacy Agent** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of PaloAltoCDL via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).", "Metadata": "SolutionMetadata.json", "BasePath": "C:\\One\\Azure\\Azure-Sentinel\\Solutions\\PaloAltoCDL", "TemplateSpec": true, @@ -30,4 +30,4 @@ "Workbooks": "[\n \"Workbooks/PaloAltoCDL.json\"\n]", "Analytic Rules": "[\n \"PaloAltoCDLConflictingMacAddress.yaml\",\n \"PaloAltoCDLDroppingSessionWithSentTraffic.yaml\",\n \"PaloAltoCDLFileTypeWasChanged.yaml\",\n \"PaloAltoCDLInboundRiskPorts.yaml\",\n \"PaloAltoCDLPossibleAttackWithoutResponse.yaml\",\n \"PaloAltoCDLPossibleFlooding.yaml\",\n \"PaloAltoCDLPossiblePortScan.yaml\",\n \"PaloAltoCDLPrivilegesWasChanged.yaml\",\n \"PaloAltoCDLPutMethodInHighRiskFileType.yaml\",\n \"PaloAltoCDLUnexpectedCountries.yaml\"\n]", "Hunting Queries": "[\n \"PaloAltoCDLCriticalEventResult.yaml\",\n \"PaloAltoCDLFilePermissionWithPutRequest.yaml\",\n \"PaloAltoCDLIPsByPorts.yaml\",\n \"PaloAltoCDLIncompleteApplicationProtocol.yaml\",\n \"PaloAltoCDLMultiDenyResultbyUser.yaml\",\n \"PaloAltoCDLOutdatedAgentVersions.yaml\",\n \"PaloAltoCDLOutdatedConfigVersions.yaml\",\n \"PaloAltoCDLRareApplicationLayerProtocol.yaml\",\n \"PaloAltoCDLRareFileRequests.yaml\",\n \"PaloAltoCDLRarePortsbyUser.yaml\"\n]" -} +} \ No newline at end of file diff --git a/Solutions/PaloAltoCDL/Package/3.0.1.zip b/Solutions/PaloAltoCDL/Package/3.0.1.zip index 032c6c6ac05f864effa41642f39601351aa74b45..646db711550ccb5e272e6054e213d242f23ba8c8 100644 GIT binary patch delta 14792 zcmZvDWl-Kw*Ddbu?!~pZySuv7h`Ki)4AD_=MTSq-HzfR71ria-L1O>HgZ~!()2C^muMkPAABwj@^t?l z%^R$y5QkFPbY*TAzWRiq;W<*Y&|J<=ysXt5A!>;P!^ItKYD|Hv=ja5$NHUZ`mo}3Z zqQaGuxL4{55iMYD2G$Ef0ZXIS&r?Q1q)r~zJNydj3yM>>AtXXzLJ?|HZUR&GKVJ*j3wd=)VOGv|~#H0(!x^a>lw4=bL z6qpZ12x59LDuwExpp*op$RD?WH+dl)aBZW+dQ?VyVw$;w4F#kKxT=FS+Cc|PA>!qj z6PSSNyj{1!z~6z)fgUa%=%d~;EsM_H0Y2b3<*X7%{x1YMm56 z>pfAG%QKZBj!CLQitZuV(8vfpCa1S*;AVgkLQCE}u1DvgmVX8me03hZ)bQ^=y$)Ud z$dAdxt<;9&Rl80A9qG>aauj@FZqX&v6oHrv&FayBIxVCEH}+}s7PC*vmQX6aY=yM+ z84(O!{G;QbnYgw-UoVkT8iNeh5>IIceT2M_o(kMHKE}dM4s-K~lUICPSN1aCh!Pyy1VqB!*jzn#{%;iO<8d;>~t-j>?nv1VA`0<)@ixpR_mGI1Vy9JIbf82Fg-mW zu${y!h!CEr(!CXj+|#pD!3)TAG*6Rm9ZbQ*+RF%}Zv!bwY7ce} zMb8mwhEz(xD{R+<^tZhDEqM5~r3v)!I`S9jHr4t5SjwJ`5dW88e{f)21JXW6BCHAL zn7x}O-?51Yhp*PCiNA)E=C`_&+oF838Ye^a)5?i{q8b?Zy*F;I>h2dhmdF%^;XQFi zo!NHKSyz8PX9+N^+?Cw_}n&jPNZiI5L8knH*F9X9VIbL!?Ok3j{mw z`SUnnDbwYIL`p?ir2HpJ0Y9&b9P<+hN~xR9`h2LBmVVw)Gws;GWnw7ULU)a`$O_?A zcZ8>WMwt!L=jNNfNJz8Pz(w-^*4RSh7Ae4977w%!=ZA;V(`1z@It35gX4`XG@gT zKz~}yWAizIHyma8EwOdy5{<5Y;p<%ksixeEtUOKsK?>H zLTH7+{i!gfxaje00SC#y)4bGr&48^d2Hhe8J5J*~iD1<`l%(c&gab6H#Dc)q%*0{? z)&xWLVDQsv5~2J=w4mr6UbAhy1O9X--I}|}fSK*pAH8>;Z<|1vij(TIgp}+&Q27mm z2<2cHNyr$pxK%d+o_YUQjRReA+X7az>4;b;W=-3PR=0mb60#Gg$y{Sxa7Lnnzl~A% zj+vogbgQ!Ir*B57=5WwgEg>!&O34cq*Izg{Hx!9u?jY~F`!SI!MMymAs4K+PrGT%hnho$5)8{auuG<{hGGMF>k3kx15|;Ne zlU(mz-+SqgnO2}Tyb;WX_BBXzD)khgnqhgFrmUVG#6&H+DfX^Mn7nGf0_P&3`*sZw z&zhC?B~F@26Lh{N+7A6oQE64@+b#rO;dN-p)NK(FWZ#la7~~doETem|f5~7Veh;kZ zW9DE`zkZ8~`wD*d7Gn&z+4f~D*mz=pX?LC)MrK!oM^tUurDpGop&#dxk!;p4&(uBm zdKIH*GF%z;^aU-Y#JUyo4xmi-Sns`0SaG&`X6rDl>ExK&RQOj9V}hxAu7D}^h!YYj zo@kq$%NOmjjHT_Cl19Bg??-3%kjbT^2{=JJzt^8|8$2t5=xyn}n&^C`r)*?y?!q*b z(PemZ8aUkun9V8zWgG5N~pNenaD~DF8wEa(gt7+`iTN z{)Cr@DM{uDFg@BZYs%eU{j{T!tEV#rS~l(MRo z1J4=igNqYV!vi%#4H5s-kvHk4*7;1Tx#p!i^0m`qKq(}t1&D6*Pz-qY;z+-G=q~r2 zsXIoq3ct60t$#i~AK0BSoZN$CxUk?KeGccxjo(R)!%#5Y<}Yn)JU!SSY_#UBe?0B4 zGL*{_uHgf$rL%|7@M_9~G$|9Zq{)t)p(|~$ctvv{stm`3?F`0dM#a2L_AkyG3SXPm zqR(uoWT1Daf#1B1jTN4rR=ZCNwJ|M27M1dJ)k>2(ipLZ!T`u3l+F$>SUNQ1AKJfA~ z=vcN*ugwPa%9YyU|1HU>z;Ufe66}n0kRz3aZ*NSfF!P<1uHR=l!+^^;B@xpLZf~lT zKQ~@7#5h%FIxn$nQb}imcbZXi_b_%AVWo$wr=d522C%>1C0j8d*&$J(Q{i~E_@W#x z_dB}ScAhdJ3UD~YR)B<)l*?F%ACDF%i>QWv)be>n{-W*hr92x=nN^!uN`as(fiR-? zAOQp1>L$1vwpubiy9(s`3oENCVgpl*fGZ%2U?9 z50Qxn<~qfH11`lF{Ts~qGAmM26=|$Z^sW4anfh#g5ah0dDYB$AU>0#{$FO8ZcF6pg z%S_T>^W9>L@$&^f3+~&*V(rg*>D|xGrgT3q15^|WRhWUNtL#M+XUIv&vRtk&4VA^k zg5ju#Ui)M$hrNq`5>>WhR_q+u3+%X>Yu_49ON$jz86*s>^PtDthObcw=X=PQC5d7H_7L zR5I+XHiumQm><(CxXa5^CAqllEE^|{p04a9^nYFWu_x=o9E#gk*9qfR(g}s}KuD_K> z*3iduL6q+(1EGX@<;T1Okz24xe6o&u(_Z|ZoP|T0Rk}34vI~wQhGaa&r!l2d6>GNv zuGap>mX?->Bg*6p(W4#;eD;TaE3^R+bWE2@o7>EA`%fM@)azi$w-UPV+CTO@+F>TQ zlPuJA%-{hH7d7(Odfd3KA|6xX-xwKB#lHKRSIupiVqOW3a+H;i0V>J$82LEw^(9m# zxOE8+%9^sXpX?gpBv*`A6JG4FX%Tp}0%jwt9(aYvp&fzOd^+8Nn^a`oFWzmobhtEI zbQ{6Vp_oUmRunmc*RvXi7vd?3lg`1ZmK=s58O6XZd6lw%<)3O zK_32VKFU;#n7i(?g~!rw-cY`9ouOd%1H2a~QE3H-+ytX*!_d8tR#_m~W1_o;MAfR0 zxvXcZ8^WJIpu?AN%0RxljTNfe&ec)sNew@?tlu|ZC@UX2gt?&ody=v^(i)pmzlf`U z_)7aAs|~?o?rM9#;-od2KCGjsj>A+2@?V%r_bfGGnvoa(HG!`HdSZetV&sKP;7|fI zMMSH9s(js$B58^bt4q3F^WvbYo9i*!$RR-{{QSNVTms`+=D^rezBwxMLVu=e)7Q?J zxU|?PFwQg@hv97y&D~Yj`VCsSHGotBd0#>N-oD?$yr2wvVG)ODet55WgTK#L!Qs~$ zy82cfO(W$XR^ULa10`r*DpYDlY;z7!LB>(ksW}!z3MgC>R9Nkr3g+s(u7gb!y>8Y$ zwZEtubH&|Ks9l$9K)N*$^W+!cNODBXcx1G@UsP~;6@vZb+P$HzUqTs9 zKKccw|2--Olze9R-_!l)oCdDyLrAIe|2>e0;Vf3WdUS&zewG238AW8G;p{J%`JrR?fGsTcXaN ze$}1E-|*;LbW>|e7s|%f>~}v$UIO|_mdf?)rOlYTTPQ0QRM*SGT0H0e`V@pbG^>Tm zwBQg6X{2MpLmiKN zKR-JZo>W$lnG*QLEsEXi2DN9gP6{pUEIneFRnOt>z_ZC`Y+!E_HyUZWm-zNE)kcRb zUBqJhccWo2Wthb4veq73=mKx``$9UqpP5)zyjllYn!hYItdB9Y64#sA=lm4BBd$LK zMYQ{C;mTW%82?(<;D1?Kd{&iArvIfzsLQ-n(6+WBwDxIQK21<2g4eFxpNOi|QN-m5 zWdxpI$_37uLS~TMl=KzdvajA|FlScSN=Dj4QmYpDG~(YBr(~>JaR$VVL*u1V*^?8W z{;^JY=5^n!cf`eG=6$}tgP@k(xjz2X_a#q2Q!hr@v$;48{qbza1-ZGS6N}cPRVy56 zj&|~}@8Y_KrdhFcm+j%C3%cwfC_zVbKU&f4CUCT|X>?f`h4d$elH1o4Zu)$tctTiW zcMN1=H}g>Cr&X+mE;8UyhAld8Kt$TTZ3>Ba0nQl9%{;w_wHAd>4292SI=&!hMtXqH zH7LdoBnvyOnknGjI$cEYg_$#BUavY?GVvbSdbU$Mu{UO>Xs-UY8Md95!hdo({?w~- z=PjA)?~0l9bEKX^i(cC7 z&CO6Dq463&zC6ncZRov`sT+NYEE*2C20%_rK53vwAX|b7_9iVq2GYLDtA;F18vT66 z%p`|z!z$F4(Q54L)QR+y#Q2pmbad@s>VTlI<@R&%c0K#Y~2@&iuToC1p^Fi&R;7J-#I+Nl8aJ?zk>q!;4M&| z*!oDrR{O7Y2EP6hUt#l)T&!#EJ-luv!iDX4O1 z>>phpqv&lLiNCjk?Isj4or}L@@Y@XOH?Yn^Qa(JvdSlK9b~gC$0#ojIa3|WCfFwVE zqD`pG{CFG<7nJFX1($}*@~-4oEIpD*zRo`PZEAD-Oz(+xWV5-0X2ty3{pbl3I*vpe z1vKQhH?$r-?4VCGZelxR5Y;20;1`^me#s9h4^fced=cI#WS>D)ERFbo#-PC^B1a&Y zV93hn{4E2^q#g>u0E#hzZxQZb=q_OKkl|Q&Q9|^K>4+lcgbI9M;kPT7E}~+b)cUqE zWsOD*i0~bsMZ~I!sIVsCG5BH%*Dfbb#WZQmv5gI7U2>VIZ{zgkD2CLdQ4h+usslK4~ze1h9m$x|xG5)T@e8D_9o zd$bj$jWhER`7RoC?3RlUUH(B1*6?R`Q!`?O5F&&<6|(=56AZEPL5>R9_ZQFB-+2UU zOq@jjB;gy#i12sb5()|ee<)~@ToH4U=^QP==j0zX(BF(0KB!6fpav)? zVxkS%Xm2p}2_Y8T`bg7!^XN^5!Wh<=$<5(MQcm7OX+|U|DFc`d&ELmtioJgr`(~(Y zAR{s4cOD-|2Zcpd6<{o4lsNOK(gaOyOITL!HFB-_b&zGruzkrJ_$~2I4lw`env!{X z<%b;5h@sH9@cgf?^#Bq7^nfRxZAx|BffuZhfRdTh`s7*YuLT(gRgaa_V?Y}T} ze^rFP{)sycsNBi?4~B?M+7Aq&9~dIdspH_fAO$3^6bYzIXzzA@$2;d&N5o2#EsFRY z;F4y|X0CrjAUZn2EGnfn4)wV7)GSdZ@2fF5st5oAuvlqS-F}n@$UpRNb7%Kcg>9v= zMRBk0T}%XD5=yd4fA4YpM?}}ZD0vzD9QzR^0U)A)-H)CB6D7f0A5l_uN$B6yW)P$>ilGM8V>e)PgtTJv`(lFCt(RqdqKl~L7b{FH@EnB27*>B89tM$yk%-D%kY z;&uK_;=TH)IMnp=`IX(x^I#Fu1%p5w(9?W{F#EYWLxAdVtUFgP6#pqK@9B`KaHNkE zDfY=Y^m8pLtzo|KYLRDaH;}8>$He)<4zgr`0NZvu=ZT?UmCDk{%lT|R=MiyKlcNR^ zrWnHwsAX1TWvO3N=g@!L88kUJ@lO_sFxn%}tguLT_Y`CNj2g1lYGcd^G)g&pbyF4l zFh}M2KS>y@!g-*0OuZ>934N{DRJ>WlWGEVeSexVPcNWu2tc-Y->UfE_T-$cx#X zD$ug>LbGCh$U1%JFVL~zOBBN`i1=Y$K6njGD>3aeF~E!>wMOvl4HA`+hNR{Rg^#f7 z^3F3AJHsofTeQ0uMbi`%P!!>xiB5%qe3}scqJrF!D|O4{c*(tp=1qqX&?^ug-zRL` z9w$18%YuODy+uCWyOYk@F%-Rzdb#xwka^njb)5&pN|ZMGc^X}FA69@v~nW_eTEa^f+ImTfQ8wiSZG42WdSw=~0KUnnsK{Oj^U$wl>U*rG~=SJo1`aRLMgwq;+zsp%x<1SF6GH~Z4AKI^c( zzXf3W`^%W7hYgBmm|;Z^TYME_bO)m5<=e*&Kl_9U4dGW3a77HkakIgn z%Ye0_Zucn$<~2KE!BeVnAxkyHo=<>a{7_wRK}*{e0ciV&y_@$WWn$xy4u8alK`YZ= zaEN^0(A+8sdlwwoWDB{}c#zm8Igo4C%<4suo*uy#N6$fI1=*=}r$o*QiGW*zm{#Zz zT37ysb8U+)zbH(#i}_?+~WTime$uJKbuWzgBj^dp-V zUVGd#y@L$ZgG)sYnguS`lf(hi%Vl=wXwX{my8MD_@?X+%W77=L+!|`JsNOHs-ej?n za=X-|3Mvun5(^jWC(SdG0|3Hlb&_AUJcuw+pZJ_O@B1!07tG(L85*R(;)Ved{449j zSGegFajvLB1I?;YjseSVzV%-J9p4xDKg(=omxvkDe1b5R^_jQLGw;wpzJ#}EaI`$5 z_Kst)e~WhG3+LW{UYKm%_a0zvyV5+dct}9ARd+6PLKMG54L|ymSq~sQasYaeO-Z&{ zpU5kxNXQb)@C{znSfWR98GkuKT=Ts65&U>g5CaX^1x-#S7V$GvY=1uEXFa-w5f-vQC6S?!7DIUjVo^i0*%&!N<_ASkpbHUp z&prN^UEu^6R+gXZ@4%MlJLc>2CO{BvfID=UT)h{&I|4aaBa8uB(w-|ZeweL{xhnoy z>Iu!3S4TEj;*tS=Nh?K4I8KNEcq8b{x1+Jc+9aCC+3mUio#a7J>i5Ao$QXwIGW~s{ z?}v_Z@QTs_0>N3h$y$ebuFnFzVVLTzM(5#4YHUtB*43~y@pIly5jx_q{dat zS(lnFXS%|sJ(}8#a{xoKhER5#rN%|?4o_5qw|jMor?Wm8Nyr1O0l|^v!zr%7mu?D9 zF+4?qV2fi&OLvSh6v%ge1ji#^idrqVqhYWTGo$i?gwqJx^k^maG(EBeQ}&r}<^XQA zDV#a0tP*+AG%%9Ojj#jNAb2@w=ifuKZw51{rd+JG&8>f(VxKR8ZjPAT$~pWq930T? zUspJ18yh#sbXrpyy|Xb+9BG-6FvtiwLCpN4KGxbWxUZ;gJ#m}<=?Y7joOsZgs~KOT zP1YSFSwDzoRk zjna8L?F;u)r4cP}gmnJ9ldRNTE-7N!sUdU~nKN5=g=ePs9}~hEgnf~@!+hC0dCDtQ zTit>7`sq&@PAiQ`EC1iV?nA02-*X1{P8rlc%FgI_BITv?sCqAlj!LItVWjXjAKC*+SqJ3!^93*^Z zhVB@qG9=@&;y32`9DQYpkm_nCxkyP4CFw6frovM+weK9&mY2&EjlDhNDJ_+*x1&wb z+T6NT#L|8c{jeQzzU|@Z)8YON_2J=(Ye_D5VK#r8H-B4ekclBQg&taYCdLm!^s+JD z&OOYWlpB3bJIk1hx!wE4l|fvz6#|rMl8Dc)9w#kr$adFwL>mmg;snbNnvhMVTf)#H zi~iZ@#}UIm5H5mOEm02hn9)Ds2IXjLpdA}lMfd->%TPH;k~Qt=aBXX4MD$7p*F@kM zd~>BYYdaQ!yjq%1O+4Tu287FeCZP-{ue8qAiP7wH@q4uHmiw&N9Ksu7MEI2xCSTwh zQizC)aks}ZGQUiW)zS>EqMMzB^QRPL>%!Mmi1{ttxDz&=Om8}cFsHC`2+g_k!; zEJ&hh5PIfP76@@uln?BcD8<@Qb5_7l1e=s+<}x0X;DpRBkSCPW08}R}4@*@xU&=f~hsxe|v#6FmY2e!up~fKB9sLqax(GgvvNwj9 zGH=NS`+Fvs7!3|68pnndF7-TrF-#F;BU-L<+=@`vQpo}4Y4A)Lq(84Rm z|G`+@3|5-6bQIrqd6bw+yhuW%cF>kQpCVj|`=F>wbVvK^&qeMm)9Gi_-g=s+G1VPc z2oVuVZ8TFf0Q^}OypsE#XouD2ag5}S!lU^;(VP2dt?))Ugx(cr3wC75l$F398+a3a z{rQB<;dAn^OZVRKfEh5YoO5OtVs0%c8y!U6A9{+<@?PG)sboX54i&te+(g}{Yh%}$ zuxTph8{o7CLfR)aNs|yfJTwa6)-l}4q zmp913r$ZWr!w#bh!*no-E0@0s!3aA>BAw^!myFX!?Jrj>+>wal?>L@Q2#qNY+% z=OA}@`H*Y2;Wl_`VhJtX2e$K(EAQ=3knxveR@OSa4_Ic=juEv@(`*M-Qayt4HKH13 z@?4b%k8W6Y31MCM&387T7ui^>O)_?bVX8bpPRz`v$Ghg+I^4N*0VlZ{CsNmk3$qUKON<)BTtGqw6;A9f6| zAb`D_UB2kM{=rEVm9l^J!A1-;mg{?mujKoo zsp?(LQE241jNJPo zO1yMs|514^o>y64ZqFntTPGi^uB2#ZY1wii1XJCH41T#fi!5s($=uU!06#XavTXhq zZX`0WBtA|%8#XlnJ0?zJ>gH!m9OH_ONz)Zl3ymL`vLhJO0>aSh^giyj?klO?Hp4^dht2?tg^H z`t~Jjq7}mbfoJcO;aSLID3k&da)X#~HAi$alGj1D%3iFTlf6HB+zFGi9brSW-)$l2 ze0ka|+r-R=+rn$A@6l3_O9KVq=Txvy{?2RJ#L2$qFfK$2({viad6Stg{8fQE2fJ`J z__Q#FnoAF;x`b-S^8Qw>;;m|eng*BIW*IR1P71wYhYvmMgB4$Q` zxF>5JOFLS6XN-OuJ(4A`_5~?@lseP}(b5GuQ)i6o+=Rhey~KGx8IXVSRM>oj#dMdSt8@X&l+j}uBXJr(g{dqC520s4D20k|i z2Um_@CETI!$7~s|aP0t2*ZmFdh#s*!0(zct*B1(_d{F@9H;mk%#8`edBI~(V985p_ z@DNL^ETofVY`Y+>?023lG05rC!Y_L>SNQ=tWaz$+Wa5Ig^y&3if$EVaX%7Ux6lL@Y z!YIVh56CL;ll@W;_>S+@sj7GAbby$g5RP-Sz;Gvzu+RJ3tryTi`$kUD%U%9*scF86#86nZCrd;2I?sVjddlu2rR5r;Ab*Yf7 zZ7h^f;oNe@TJLmYt(PD;iZWMVMvz)rFd$48%O$(H-C6(eR^dr z>oy!a^PqVNsVtAgGJdMIpu)nCQ;s0bD#*}S7VsmXGX>ZVOYLmBtBDMb+92$~gZ`_r zF3ZGm8Kw#cDaZ2H%<*EPYP9jt@%g#wFM^ED!=55_94Y60_Zll6vO@BeCTxYO7<#S- z)^;U{9KH#*13quM%uMp)&lq|tfD#wKU_FW9wYIYR z5TooHPAl+*%Q*eFxn@`5VAj5PDE}PEY6iEkOhu{Sev$Sn^<2X~^54$MjK75x(JU** zx@z@_1C^9gd$Sve?)q7wYT8YIsFwNID_Lswn4E)N`x zuBudP^TF4hxeh^nnZT^(X+=Eyq$UOXAn-wm1O@K*Ks#TmRyPnrMppBlGuobV4_Ov{ zqCG4{YISL3w?|;9U=sq0ga=vOC$eJ^^X8ZN~{C`!N~90uTde?1g~gxQ7A5#P2V0h>17EMO@F zf2aLj`A|V071{NwAfiQya#Eue*4PA2&mWjgq7NO`$XB_5!R6xXIW0Q~U{NyGDbKk9k=;NfbMGlZt<38sMYg z1g>viD2r?I^(>(gy1e|WFSD3h4~(WgeLX1dAKm3XCL)@sMCAk?QRO*O+;L;5lYO_( z_!0|N0Rf=Xz{;JTWGYW=wgpIgqW@u99r;KEE!G%BX9Z^|1&@Rh;uS!?}8&CozLtiaRi33z6&sfiSWZ95@PT z@z4ZIkIj^eUuKt*P|ymNoFWfFy$GH>44#ZqrZLa{RHkFaEK+RGaRgCj*M9jG-01jr zL{i3fB`{Ud!UIjJwZQ_G1r_=Cem*2iUrf(fJ)Tyt6Q~eLi)QOe74izJ4<(UD4s;N0 zKDs$fPhuqNq79&r2+YIy==xK*EyRt(6Jifj_676s1*}Q*!bqv3-Hekd(^bI-te{CJ z*%ZY7&*$eUyBnE@LNI}?^NUK)LW{v{}l0hyF8 z7uLU(tj+CwLF0a+tbg-Ai`Rs;{5Uh}`|FenchfSngj0w=rQ&F~24nmx|NC(&g@ON)u8ZBVW zu>s?MRzRN*_?x^rZdcKamUKuv?(f&=9GQIui&&bEZTDvI$ZIl>`}yNK!J zZ@SJdL27siKb;p1g4IMY^BSLyYnf3YYz87%rAf9(H!n!uPaaBvC5 z8tE4dLE@z}55jMUb51SWf8{XafArb;{Y3urkG}Gt=shII>*IcX4n+`@;`Pi7mivoV zRm^!uLw&QJ>BE(AH4PMc-{Ef0@9I?aHb6MK|hppD?6l=zbwvpgRYZq0o z)FRm~ZZ@@t6^4AlsW@{cr~_#Bwty>)>x<~rc;NLaFd(-MkZJUNvPn3v1)dd#YZe%4 z_X_R2^N(mLp=(S-a)m`sc}ii5wvmuKunZo+?G383{U3dtTbsW9u6Dc(>joGnkjXna zzXNn;1=qjo>1wfn=T>sEwr5%6rhcXcEVn(i5F)bC4@>rd7bqj6C5tEP$!fWqTGKit zHx>>X^U}I$(P~Uuk|*k;VLeIVcb(;{NRC;Bie>IMTQjSa?LP%axU0~*sFZ=ku>V_p z#j+(-Yzq{#(&uRsVUTej-KU@;wnv-&muY`|WLnCikGfj8o8yvck?9cLQ8VoW{GW;7 z9=3qQ83hh#9Zibd*hB(3seBzp-kW5sP z9bVqY*H)1iSD{Clzqtmj@T6)4NTV;gA3RBDMaK6wETDSdw}5w4J{m(U`oMrYG{zUl zEu%lG56t7CbA-V)B&LWpsPYPV7e?5ES7Q1zCoG0a z4EXcW8??hRgKdD$`q3A8MEguQWZ4pAk_U(e^=GuV`jRayO~aiut|h!?D%{>?bt z43aG4qJrD4+4nPPEprFqTM7(Lm0sTifsL%4p)P?;+|(B##5G;DxI!?VIqxEzx^A9P zhaF?kg0qws*dArV@Zi^D0~ca}8U&HZW*EL#KQIv98KRmekX5bu6;~eA8&Ee;#R0h5 z&{o7lq@b^8-C2iog+wIRMgkd|`L7*JQ0fOgS~Hf{_f^{*l1HpLF)*|-QdCbsttAL4 z^5?E)uYUoLI3qs_%-SI#+YZeG@>q|B$Ou*m62+=v<0->ax3oY`7F=+ zWtR(3X2}n`Mpu*`Wtlv0RgdX_C!TIi>gXxXHz5VeodF;dhG&H_nLeX3GbS9q1zO}p z4(-RFGzR~>xNu*x#Gg4L36JClzhkD7xwfcwX2sc(`Nv>!W?B~Ea_@S7&D;{puFzfn zBT2^B`a`3n4$2qG}Mi}@JOIEznMNvsvP9qGg&v!*3k1lQLYf+S0`WAOGs=V z7|rP8fv3m!(v0GC6x{M31u&9GCgJ!{HYfo}TI04geNZmTAj0BIo9-xTGAYW-UMM{d z7zVjj6(4wWJ%kr$CLEGQV*eDBP+ibB2ru_=U34iUFi$iR;;{l5^bXjqdby!T0^?UK z!}^T&zZ~D+M!vsRv#r&Ot?yWFn@h*-!ikg5w%LDkgC}A2vQaH(A4PuN z^r%lis#M%;EAWw)y9@at@O8}}SNcUXHcqlE@OAy`&wlg^fvCpG>Uq8{pN|cT$CU!h zvw8tc2EODHT2{f2oqrza~2*FjVZ*C*_c9 zpQ{}C|D07!99Lrm^exiOzZOrhs1`33(%L^qB2usD+1wx!AKuZ*t>thGQRy?-3n@h# z#TGQ2<*5B zvnsQysRX#Y1Q=668Wao_2nYxYNY-{jqtxZK6&LQWBpru|570ihUFSsq>h9?R-PI*@ zHCUBgOLL95gzJ#xQMP8DWIufnSAzQ$-qe~anpCjo*#`ck`84|^`Gk8Wra3kkg$7Br z#+pZYr_=4^F5&xnpAB{Tq595(J~stBmxhIMj?r(p#tda4T1;yahczScV-TVXuHMbF zg=Gcr!lTwG1&}!z`W~U!ztzoUfP(MPZ_3Ik6|~zO90;($`YfDpcAET!3RPrZMRG+` zdN=?l=4x#oRB=zHj1AE@l{8wn%%sX{0>Ld5!>|Gt)fGwZt;H^gvP|$opaMR_nJZlH zdut}c_T0FRg$-KdGiaPJ`N4rN7q0d-elN@&F$Jk?3oskyoR#T~gdhv5tIaGB=tTK- zfQ%x7gpS0;8%NwL^mvmB!}UY#iU1cOI8$nUNAcI~jRTVS{5?Y2eb0o!lKJ*v_O8Rw zi?dn8F~M~H{V%U~b&HkXmo|>Hn2V8=?1mATk`s|};i$q>9;{@>>~Rsu_!c6;J?P%m zECG74PJo|NBzN84A1NL6AXOdY=GPkB+;T+%u1-t^#4YJ|`Izlluhs@USA=k$WO&6a z5MZIszzqrYza^$f`WodnUQfX_O7PFDyE64`yo&#Lk(!Mu)JPm)4fe5(TAU`d&^Ol5 zR{%#~LlK)x@CfaVR!>Y6w#|U8P*SB&9|vN-%Tkvu+N}9dp!$d zjma3eQnS!H<&C+I0y4mrz)2ZxMzCal_VD9EgUv0|$c7yq0ed;wLt-vT`>fW37{mb< zy`ZzgTxUVG{Bru7B&)1Y@rWbVGCpEI{$x0VHCa{0;z|kv@(vZ^K(Fm;ZV@PZc9_~X8#R|=uCdY@jKs;2El4W`UQ(&7J zJRnR5MV<7ePrtmBDe{tK<}*<~V^F%gk_EI7|7lo@(|R>CczAk13s58}P7_eHx^xuA zo+vo*jdjv+1Xal37VrNs;otv)10q(YzX7X3W(>pNA4v3z#2_3{WG0h$eK)Z)zqTM4 z2~q$9B~L#|lMxj(A*J0gN$fLs`YkMh1&1do;{0RyM5))WquG%wz>O2(3Al?Dj1(Y9 z2Y^rm(!=c)$iew38$gP_A-_7zuwtJ7s|x$qJ=t4JII30$@wheR)G%|JzaW+Xi{{QstQ^j8(N)&` z2J>n?3q=CTdHC|B*8AlwLS|$^&1x?o@;C7eZFkQ>G$e4nZ#Q zYD9FDF&M=jM(f3aC<4YspGL-ozV*ns_fGT*X3i=2tHR{R@=0+jYUkSo9bun#{tvgD zkL8OL?;U1UTABVyERq|q0~~i=T(lLo|m=onLa-#>LcU^0B6AzX68Y!y}WHzPJN=hCw5$0 z_S%qd;X@na=x_|cyKWtSj<=?+(2+I@HUkRC>89*TdwjxdYNogpnE3&IiS={ZGfXHe zovYYJz;rBB0nT*JMvo$ttwv{LG*AXZK+1bu7y(cV?eKbo%h5ki&}4;0Gy*CFmz^!~ zLczNgfvKBe;4C&|;p;Nm#NEozfV4Y%$y~1!D)eJIK9G&Miw@eX4u~R4>fCZ(^|B9a zqMnum5p-=eehr5+1-JlMXx82wv&KF;?)N(C7b#XIeHSUTkN%Z_iFHHK0z?{22;>xJbm2o^0e3dc$)H+)G>|p4ygico<_z8fgeur8zKaf7EK~&lz(qJ7f$sunkejw@rbE*ow%6D? zC~aCstk;+jNm!yGi!LB*g5*3=XDC%NmFmPyH$Rg*>sfib^mSzcxch?by zhxkKXuD>~K+0p)ooA(^@EGwxG+gVsSMTP1OC|VTT`Nx?IO{@aRA*jwqie2tv8Fam= zL{}-IK~-+8jvFU{CRjZs_41o!HfL^G@}PLNVMnD}zrx@LhL;U2DuspT?wdCq!Bm*& ztA?^nTwOBon&OW^9y!BlH8|Tw=SH?b?}J1CZZ({;K6-+PgS#Vl?Qz3$M``h&3YP+Ju5jG z^=Esos79~~lvt`p@L<+&samu`OWJy|-3Z-+@Zg_4i-s8KNe&$X6bDj*o$dQ60nJw{ zbvx=#uaBIKl0b8uXnLvWO}wyBJFt1K#)Zf1RS z@N$2{Wy4DZQYebT{`#B}u4zS(Acm`UZ59GIo}l$9*{l zDVkH^ILvLRM)`or7J*sksNG)FUxLdMOQNK>&+Acmcv=ZFvdM&&yTEol)mpEoA4< z6(}%vt4f$$j&*?X>wdk)cQR6g0iD?>egMyZ@ zz@IpZI{HW(0~Obpo2td~997D`I9=D8gWHYyd&Z?UhiMANB>+PqsNW(;HbzLRZ^{O9JiXS6O_xn`kmy z^>OF4hKjKe85IMR?A5LwfvF;VZD? z9(X}UqiGCe^CzGqQ0*_Zz6|%ZqSev+_-Fub#dw$9$(GjgBtq1wq7c)imAaknJUGjM zYB}c#A9|F_f(~vzW46-YJ6B_L1QAc?G{f}|H9N%*6*=S1rOkz)!AWw9%vUaa>U2kH zR9^0Ao00tS$nM5u>SRxuF=pfXYh*~Qt9(HfU>>HLDI1+t?W8NiS{suq*162*Q1-J* zF0T3xf{fHq^%T?w;7MVRN#-s|X%dN*`aD43M;l*Bp4U{u! zao@H^7OGPR%L;_7J$k9@DT(&F!UmQ5#=@S|(pa9ssr~2Tk+a+Ngn8cVUxV)K>d!7w z=8n?Hy!2j{r48N&)5nF+gw|XL)6<;pRh4aSX% z=<#ya+IX?IMdf?fNSD;pqQsc(fPY5iK57FPeAAuM~r}=2}t2&Jv zY=3I}ZT{SUw!jq^T6%kevbJl?$;GbeaBZ=ndBrK2b5NBUJ#`uXfPDHgaUGk-r=l*n zZMi5er1NhMm;9NkM*+0jXfBZfSjVx4mt=SPXsIYH>!EQfhT>@!jMvp#G}W^);>!9t~$S9#cjvq4yz zCK=q-{l0;-{k~p znBOOvI1o@MVZ9R^HYQ-BsjA=|P4M@WBN+G-dfQaue|j%Ho(^E&NHRwV!3*l zN42&mO3X%zHq26Ae583aJC%?*6a^;a2Sg>+WO5^JBq@lpY0ZjF!0-2ppNKCL&lD)H z6G(}U&iN&LI`@<0zG;t=Zv+r6>3mzZc}< zC;jUz>O{Dyrt_T}X9GDoE>NIz2vBZ$xTOK$UEi#IXJ+<=EF;@_~7| zpyEjFU4okP;Pk5@z5Dw)qU`98Ki$?N*yHn>(yg4Ya;NAWY?%_-JSevpaVbS-o&Ap!eZ?6HqagB)ZZ4S<$P9Z`FXa|$=fSHAF=1Eo%>h2QKo8870-;C>; z#T2!R;X#DTmBR8S1zQzMyg)vuW_t3Wbiouelf~#4cwImkQ8t^Shh|57|5(zp~5SVQ^S>EQryS45((7?3*68br2N~UFcJNy|^Tfys4GMz0*x2_~r`P#U@C-7VHD_0&P0| z0=1a|^2m#mX7i(EimKx$5Z9Cf%XF0qP6Tx3l?+WY?}|4GQ($@{M++DAyA_EnakULa zv|0*~?`7F6*K)mDc_|^T87!#~kJ<xSE+g}nU z#etn|e0tW*~qKdF(m2{jXaiezaZXp6pt(UgqGCt#33(=U$K&r*Y#OYFy=BjgFHw5Wj27Sguxl@4QU`pIxO&035@c+6ThgookO zaZ1;mhv7JqT>fdKz@4P-Mq^$5YxDqFK5!#3(O6X#*QvV^Azc5{ixWYu$?ZSN|NW-@ zq%0nb4*ltWJ61Fphs=*N_2aQ@F!dwX83tLU?nptjh&nVFdRwJ#foL-x!?=p;lo{J{ z7+5!(6CXYlQ%Kw{DYo0RXpu=ZPeRux6pL(LMFf=siY=Q>ufmB-f|p3SYyE%Om|1fa z8>G0mTaGn`TiVFi(r?O$l-ddx+KT3~D;DD@7v1l$$AleCU)EgiqKaI(0R~kD`ZNda zHhb5d1l->-v4NBW;}}7^z7%*tkb+mlMe#?a{*2o^2~Kt;ga4VeS+(F%|g5HwfI&B$i`?2PY@&iXc|L(9TTsJ&+)DNU22Hs z``%jZ45CDDw_t&46b(<-;k*ho@uwH(C+(VjZS%948|>HSwi}MF`5$oT{+&QpjJj!< zgVP{~hgS6NsbVCrKV3-jVVZL%RZ!O@j}>Jsn>e=NHl!WCfQl2)kl0_dV815M2bcA28qCsPYlB5=yWP!O zG1O%$t4V7kj<4v8n^RA#^!|E%CqhyahRT=wgj_zL@$+sHaw|;nB4H>(%m~o$C(n#H zS+XomQs0?Gc&lidgI`Ic&#S`RK0hm)0J_W=2AS~P7x$wp!a&A-RlHlE&;a#jwth?r&aIrD#SAKJ>>X2=a2-zBjjHcbBP#7y!INb;+7w|7X75>IJLwr!i(n)jW_G(-i8D=S1rt z6~&|yf^Krtqz0iv zc!UNQFMD2)SC>!Q9ZseA$UfPdWcg4lwLB0JpaF$U|5bLJ=l5;njCbr+uw;^-fi)PGnE z@W*8W!(A8=|0)G~{4bV?e^~rHun+3TgP#^w>`P~}mOLwI*PMO{dLiJgp}0mqd8bF$ z-H?XipPce>Ai6sZIf;3g5SXALR+F|)qaSjq02VCQF`R&hG$pkYLti)|BcR?n*FmC| z1&Zb@+*?bQkPss~C~^AmLT;f5Xx6ts?@d`@uaq-?$xJY(58lf=K`KaEhIeqD6elPg~z17M(rocXzGVLhs^H)A< zX>J@B0zZ44+Gp1oZyb-a_S^Ac;ckL+ao$yMSdH?JPph_2}{B^6Icz1n~4Mm z@##H$mIy1`hkjHo|{w1NeSESiHC!kF~wI9YpuSp;A7YA)!(NT6-de+~p8R zgV>OYqkvz~eVnKz36#eQge*Vqq%u^xw2)v5F!5)M6mqyX&BgpJgBW1I>n3DUH9|p% zLP5AtB^0Mm@{Rtq<_I?R7J#CT5P$2^bCwLbO2b1oE?JrG<}5>So-_sq_C@dJI7!S0 zv550~A`0zA1DCZCm%qG8#lKq%_IT&nG@eReNn`PZ15nO^U zPh!BxyXxnkKDW$VKTM$sgvk*VkpkL?e~l`AMQe^9KQ z(gD~LuN%w(%b83#p*CwH^pp&RNyB6Q!vUPn0nu|31sd7M1tj*;>3_kuFrCgt+D=gZ za`Ybzc^v;R7}ED}lB7YC_FV(XD|#nDKx0brak-o5oLKGcgSORQ#jQ%1(PJ?b5 z)%RHajGM;GWj}Ol%%`>&;Vy9=s@E_tcV|#P964q#5Fzs@jX8U=g`QJ8r9COwL%71b zM!3@y8wrI|J-cwQa}&ymv7{CJE#z~yn2q&Ziq=heFwBi(7=ZT_i2Jl(L-60fJK%E# zGO=ogz-F#p2e2bwxtomrl_pe=2JC0g?S?Ckj7cI#tssw8XTdY*tRYY3-%mcAAy7K0 z4l_mNfg+zoZQmadn-P74ktdS)z%wN>*v36x?JS#$bh$hoZWe}I*i_0`(zMBe(NnJu zQX2Htto##ee}dfY!)}*p6{wP4JrXbPv$z7Gwv`!ln1UUy9@*!H0$2lkUn-C$$cvCT zkYyb_Y0sMp);AAjgFv8fCWt-9D*=<4)bx&*J_PtpWN{!NMjfX^e0zJ_PCh3R@+Yxc zfU|ivW#8Aiq4-IZV74sR0;9R)DAsrv$E|H2a!CA6G~?H9e(YBduqEnt;h-*LZFZSm zh8c9Ls<#{DqL+IV%|jsG%Z7BoI*?gHE;Am07C~$s``sf@NWu%0oHGPE+!}Bz*dMgU zBx72+dJ;%j=INg5=bDGZ01xqy0T|4|_7sRZ(capzt01~lLj4GGKq3hRbhr}*Ml$H3 zqTh9iqy~?&Sb4_aj1%m1-+r>MIxM$1kWK|CU_b8)sU(T>`Ydbi(%+JcAVgaN@zMcQ zf`{XQ9I3O5D={37qDmHX+QD)|)Q8WaK~7LX9TfJr%Kj9^d#)S+77d%EUZkP@!uzY; zD+}@Aw0q&i;zBN9+qUn(+J0ijm6ZH^P@uz(S}iPAOtKXA4KW5 z_7dQbs`)O`DZHb#znw&|9wnB00gbeWO9m2u&{|ER04}D&nQj$&fH;V)JJKtN?4%Ru z+xHtD$qq@eq5-n?Wb;7ULS(?Lt(8sD-SLa_SVaX0l`!*W}uP%Kw_yz*c{TYD5s3r`Ox&c3WsyZhfUd zJ!tV8#YWEt+XC`HhBH_hj#EG~oFK{VzY}C}cDSwRq%Z|KblYlK8!IJ{$3{J-z2tLs)scgbr4EehF0^RGR_#_(xq%9=C2mC>Z z9KZp^!TA!Hadj4qdDACb8x}p!glZX=wU(v1U*`-K1iYuyM?qo;<$i$Qbb82ntq?K?U`p{ z>xWe6a1uD(C`F`Cs07YFe-Bu^UH1qay#C7E(|mVs374wh44;BaJx@LZe=up_^hSKp zI7okZw=O0inPRZNi4MbcyvXSv_FO9YN-gRo2?$_z_pt_=_oYKI!91rO_|u{#y~%E+ z<@{(3KWlZW-WCI3pwZNHE8V%!!`sT(y0p0Y(ML~f5NxcAWitXL&!Kx24Cm)QlL(q4 zt};eDs0M9n9^cbMDEZkvb^rQ-}y0J#0=~_E;gKEbg|YOdt02J>I%V? z(1z9KW|{%e$Iw<7CGo>zu*r6IAUaGujLG{O>J~BOS#tk6(@4LM?(at3q z*a`GZAwM3Rbf+Gct;we9({Bs_5`m9 zX69w`jix|HpS5KZMq5^-6o}oozM|U&N7_mUk9j057H>02-a(pze$J^Q_5dl4QiME5 znj1katHn3qhT9#kd7zf=sIQ@H+1b-$G*mz^0$ns(pN=6PU6FMb;yxA@ulq`P0uKYs zcVN{bEE&Zuq36c@G*XJ%sy{Ez1c#8_aSe3l27^v90?~gyp50M_PXl=Fk>V zgF4JW(#1seT<{am&R(_+HUM+`omsZJ3{sNzw$j*(EcxmTqp5tqFcTt%bj2&m<%r=% z1Gy}IWzi;zVY)aPNWokr_|HwU0s;XELfx|lcGw3vh*z&Ul~KWX!K5_TbdSzn>F>0+ zZ5xW^y-e*SKykV)d)P1Dg^PRIs#%2j zkTvB6t0?eOW}`gwYSDT%puwAVqSOc!T0QW7gli**(Qzfqwj`P5)x;566GN!)W=5n| z;ph0jSa~KVTyf(87*zPoL8{{1%U!P!!kVTd4a&8i7}uI`h$~5ErVwH7h?^qK9yGT|6ki4jL3-X>G7FRt%Yy~zSm5br zF8k)BfPUJP47eigb%cDz$tGQ?77M?VpfgMzcZ)aJ{zICY!c@2DG@N}&+FPc6_y|Ki z?BVA`55+gxiYuNS&ANx9$aSX`JvSRM7q@=hN``JpL;DFGkfh0`S5Zv!bwb)>`@qox z&D+uZ9ko>cY1Bz6C(W|NO!Wo0<@>_=#PDK)^`%|rKwREhA*lvn$qvuDxZ`}l&BGau zGC=|h3|NR^o@<|cI{qF9VEe4-&t+mDPbciy1Z_iC()$Bam468TRK{^54ObUI1&N8Q4cf|0uGZd z-8nsOA-pp?qT^7LQ&{8r?*gtKMpVfY(8MgnsK?LgdPmCVdc;$8DlJQdjfw4M*BSRq9WTW+X8c!1;BqVoVC^8ti zy$htdC3Nv|e~Xqdo8JO_V!iPo@@Lg_UF-tkR1~ge)a2 zU}6eek1V;rsvo|(N)hzQ5@PCESk3)O8aiS*#UpPxhHT~=QTT#xlUxXd+#J7#K)Go5 zbC#EaA?Zf=C>WB%mbYc>$~aB>sLSf8WZqQDR?SFpe^n*ev`z+i-}e!pgV{ac^VJM$ zj)e~(Hne4_`{KLorfu|ZiA0Rg*m|Sc3@gpfHVIBsj=;EVHmBhqWW^Wj0YX~)8Tk5g z#;9OuxlsTEPXo7U%$^b-($%+0&m>;hBz8!I zed#CrKjl8Iq~igG6*#iB^v_JVtM-0EhGJk>fiBR}L3d0e9ncVXqGp=zSkDJ99XIj* z5-*1&tP{B2FttO?0~*>VsZQ$oJ6RGdgw(ZEI7|25+%W8;dv-%MKIyw&6yT9`Kh}o~ zQKO5E8=5x(N!2*LpArq^qGchw%bpeaR#MI-`Q65jg&Y9k4C@k8lY~Ckz*7^{J=r8t zmoRxlF^z_<(AQRX1w*nA$USDr^)M7lPMZKSO|EdP_uRF1WPF@5UCq&WwyaQcXDBX9 zi=xWGLW1ii(+VaPX+oE*;$iCzx8=TC2;n6HogR)ycvut&f1t0HvS?GqiR5>&^a0H#UAJBE6^z5F9}6Zei``fHGG} z>;$Feh!KisfF4dyFg+RoB`HLtV~p1(B@}9ZcL846OCiJA=o?!_l@Y%RpHueO)k@iu zv-gz`e+uY}Ee@)8JxTGSJ4DgO>1Psj0sx*JdWk>OfBk;c`^66nhssD*y$|pO)iyj{ z8!(Dc)%kc-|3$0^`i-wsETl#)qvodC+@rLT{>gENy49CRd5d2qF65j7&yl(@nK#?8 z(%u}*28JchuSvsCeoochO9<0CrM=Zc=j=)TnP-u3XAviUiy!z)=wN>E`gbSdTb{Yl zkD$!k{%A?7fyh;rH9xQa>#Wv#TAL59)@p0|lUQriVa`$eFTp z<9BB#M?3X$Uiano`W6kL;cfy)nxOB(3aDMb0V|{GkUCz4SgDk^f?`m;C#9*MYKv)u zIq^?*Ee@WgR`|wAaA|pses23WE{#guLmbS=!EdhBi-(Cew^9AkjG+RYwSu@MmL761 z2g$qUki%^T@e%;smcN5!z#zYbzcyFJSqMfTvbWzB%Oe`Bp>bE)gK z6-x3qwGvGafarYa~pzAX+8>P*?-(`_4$B=iegHvA#Y7*t)5? zi1r3tJNbpaul3NE%Li3q^YR*Og2XlUp8$WS&C&N|X1ONNi}CZHCrBKqJ9P(`;!#R-YssPa)7)x$H*w2}iO6 zgg8~n*AYbN_2tq0FM;H}tkH18E(A@a1sD8B`b;fYAc+Nt!)T|$2@&;>!Zy?qJf8^b z@(x)7M<&f6f6)U7>kcm>!(9lO9SQ3|jF*gkM=)&CQ8NX*mq;#!}pxkWpv*%sJjTL*!x?4azpDq@Uihr zS)>qFhnMLhfIw~w{_?9?jgxN|Q9gO;q!rZch86>CAi;mxf3433L%rwlc zD+K(jJT!!7z?ZG5m_ZUHNNc;QJofmN;d836U0|y6McERj z5M+j)KC^_CO@DkqtO9Ee2GU4gQ5%&(u5td4rHioVq6zW4Aw;H-CL({F;6feaM#6K0o5mf>QjK-2mtc^{o*_Dv3wF?q{wN43-N{sUwTp@0d{{RLC`2h&$TCVO85^GVd}d=8qrGs#=kLf;>f7ZY3-)IQWnxMe$L53@V+)+2DO z4zw-;!0@+BRt{y^y%6G}=|k*nDs-v6grb$dqT^Thg==`;#!*yDV!4{OS{yj}<2otR z<~LPsdsx@cmMe{Qdi(QX;1WF9C833ws(`=}JW(5HBJMD)7FwI5k-?a-wy{%|f@oM_ zU43duKCgv;JWyOVgJw&IJ+tJ>{mX;12wcF~nS%QNCe7Ra@<2{eeNm+ee4@hzbtY(OncH+u1p#BFRbBLH~A#ou)6 zcHlYdh>6hQb2ybAkt=1F(1i4l>s?P&QMXn5K#}o5|eD4vNqz?o5Ydi$Tl1NXIXz*7*SYA@wm#n-~^qEq<1%7214J zr(P^N7Ekh}-N=#MNCb101;GDQ0Xg&k+7H!SMea}wD5`Dfn3xpL+HdHe{nGy04>YP8 zUU1(Ek~KsZG)nS?1Q*<%;~AT#5v4Ao`akAl?^=Rz`e(ky9x=xd4iA?-y7VHU0CJD( zUlH8CH0t8ddTXoNm5d)R*UKmYVTKR41~9U}%AxSgS4EkkS zY!o}=<%V_Pn@c^6WOTl&xgk-_LlK8l-%-=F1aGCTyD8N0IP`c91oIz8A1bb6Tunxw_G)`0AbTyrLM4K|hoLz;DGt4ql=k3)_>b}`eqtu!Ed=w_~LMD_LLBqHeioX}+*u3biTGExY|C77uHmusM+ z+1P~Cq127>6=!`j3LDf`;&I)M3MUl`C7F}Lms@T{6;YQxZSKyj>7mW zILdjB!a-ND+QCiX0G{HFx>8eze|NUQue(uzwwyTT)#ZdLV5 z^hYzz*(u(jOk{uu8h0dg$*_W_suE{ECp^m-08vqoIshMZ>Xun(DIiZSvLMBQ+_xZzU@P8@8Sg7tlGe}6D= zQ^ZuL0DYbjrM_%;bx!2p=%&IKbATE0^=Z(2HYdo*NdW64q{y)Y7|}mWz8~%1HgP<* zL4T1qp%5d-bT(4_G+>_F`ADmYPK&2F^g_8N$2By7r54J+nNx413S5!LX*4xQ-F_6@ z_G0LT6n~~n-y%VWCf0xUg8TEs3%Mjf*_cwa5>ITV&C+fMJyQH-Tk%Ei#))b03)%DJ zWL|Oik?#h^-KeD%fa@HE!U`vrfExIF0pVpeLdo9hmoz@%qzJ)250TsVpHL!JSr38m z93G@+vFts{0XNRJz+}7p82=Q}Uy+-=?Y-Abw6?!0D&4tBXsa@pFJgluH_F{oBA>6XQ1=%zo z_AzI@QeZs~!V^_ja=%CiCjJ&JpqZ2{D3_`wIfo!+DL<+ix7ayEb1zvV$y$3*_b9+()waX8%qFuWg7hWf7Yq*b^{3;ftxHLT{Z}1szz4f#cY4 zOcYx1I8d%o0E1XY&`yjiV%uTJ0=;$`2=t&*MT}BHI**|{hDZ{G^>>2MA38GzFbUS& z*a_IZ)3moQPLU1>MQ|+C;s|+LtVx?#IxQRs*EhAuJ7WbT@E~EsBtPgQdd8xZTsKwR zlRxQHUM%Aw3JIPg2x>((2X5Uar$7ATxV%dzY!y%X0j$J&AIlbg_tQ$Hd82K}5vhLK zKn+!3ahBeswfEf*fqIfA{C7e%>fzJk`$j>P(sSp`6gJ6!riBgy?jj4)rPkFSEt;OJ zIJ-nF_F&Bh}vqQefE3;#uI0aNc_%kJsMH;6<<%Nz@wEiSrH#RN37HS=*{FT-J$_#0>ORq^<$LfFOWu3nd z%yqTSKeQ_E&x>>JaVn?E;2EE|yA{trj;Ky#Fr*Tt%02Rzv`|K28V6l|c&?u7=9RN4 zes~ftS*KB_m^jBVxK+vl%v|2;ONSG6qedGJpjDW%r&`G-lhX>9lnqx53(8ZOzD|MRj)(vvS@?kSOmd|k^1 z#}>J>;>4-hFy72O5zR@MAmA}=1{*H1}9MUgM_Tub#x^ZP1UN2js}E#67;`N%7jk72;e zyTDifH>83zFbFEp|L;g;LX$EF!T-B08Wafm@7c?L7cdav-&QdJPK6YrQ2F1J{{xyL BacTen diff --git a/Solutions/PaloAltoCDL/Package/createUiDefinition.json b/Solutions/PaloAltoCDL/Package/createUiDefinition.json index 87d4931541..fa07fb91cf 100644 --- a/Solutions/PaloAltoCDL/Package/createUiDefinition.json +++ b/Solutions/PaloAltoCDL/Package/createUiDefinition.json @@ -6,7 +6,7 @@ "config": { "isWizard": false, "basics": { - "description": "\n\n**Note:** Please refer to the following before installing the solution: \r \n • Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/PaloAltoCDL/ReleaseNotes.md)\r \n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe [Palo Alto Networks CDL](https://www.paloaltonetworks.com/cortex/cortex-data-lake) solution provides the capability to ingest [CDL logs](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/log-forwarding-schema-reference/log-forwarding-schema-overview) into Microsoft Sentinel.\n\r\n1. **PaloAltoCDL via AMA** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. **PaloAltoCDL via Legacy Agent** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of PaloAltoCDL via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).\n\n**Data Connectors:** 2, **Parsers:** 1, **Workbooks:** 1, **Analytic Rules:** 10, **Hunting Queries:** 10\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", + "description": "\n\n**Note:** Please refer to the following before installing the solution: \r \n • Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/PaloAltoCDL/ReleaseNotes.md)\r \n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe [Palo Alto Networks CDL](https://www.paloaltonetworks.com/cortex/cortex-data-lake) solution provides the capability to ingest [CDL logs](https://docs.paloaltonetworks.com/strata-logging-service/log-reference/log-forwarding-schema-overview) into Microsoft Sentinel.\n\r\n1. **PaloAltoCDL via AMA** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. **PaloAltoCDL via Legacy Agent** - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of PaloAltoCDL via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).\n\n**Data Connectors:** 2, **Parsers:** 1, **Workbooks:** 1, **Analytic Rules:** 10, **Hunting Queries:** 10\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", "subscription": { "resourceProviders": [ "Microsoft.OperationsManagement/solutions", @@ -463,4 +463,4 @@ "workspace": "[basics('workspace')]" } } -} +} \ No newline at end of file diff --git a/Solutions/PaloAltoCDL/Package/mainTemplate.json b/Solutions/PaloAltoCDL/Package/mainTemplate.json index db508bd5b5..e609edd705 100644 --- a/Solutions/PaloAltoCDL/Package/mainTemplate.json +++ b/Solutions/PaloAltoCDL/Package/mainTemplate.json @@ -1716,13 +1716,11 @@ "instructionSteps": [ { "title": "Step A. Configure the Common Event Format (CEF) via AMA data connector", - "description": "_Note:- CEF logs are collected only from Linux Agents_\n\n1. Navigate to Microsoft Sentinel workspace ---> configuration ---> Data connector blade .\n\n2. Search for 'Common Event Format (CEF) via AMA' data connector and open it.\n\n3. Check If there is no existing DCR configured to collect required facility of logs, Create a new DCR (Data Collection Rule)\n\n\t_Note:- It is recommended to install minimum 1.27 version of AMA agent [Learn more](https://learn.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal ) and ensure there is no duplicate DCR as it can cause log duplicacy_\n\n4. Run the command provided in the CEF via AMA data connector page to configure the CEF collector on the machine", - "instructions": [] + "description": "_Note:- CEF logs are collected only from Linux Agents_\n\n1. Navigate to Microsoft Sentinel workspace ---> configuration ---> Data connector blade .\n\n2. Search for 'Common Event Format (CEF) via AMA' data connector and open it.\n\n3. Check If there is no existing DCR configured to collect required facility of logs, Create a new DCR (Data Collection Rule)\n\n\t_Note:- It is recommended to install minimum 1.27 version of AMA agent [Learn more](https://learn.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal ) and ensure there is no duplicate DCR as it can cause log duplicacy_\n\n4. Run the command provided in the CEF via AMA data connector page to configure the CEF collector on the machine" }, { "title": "Step B. Configure Cortex Data Lake to forward logs to a Syslog Server using CEF", - "description": "[Follow the instructions](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-from-logging-service-to-syslog-server.html) to configure logs forwarding from Cortex Data Lake to a Syslog Server.", - "instructions": [] + "description": "[Follow the instructions](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-from-logging-service-to-syslog-server.html) to configure logs forwarding from Cortex Data Lake to a Syslog Server." }, { "title": "Step C. Validate connection", @@ -1906,13 +1904,11 @@ "instructionSteps": [ { "title": "Step A. Configure the Common Event Format (CEF) via AMA data connector", - "description": "_Note:- CEF logs are collected only from Linux Agents_\n\n1. Navigate to Microsoft Sentinel workspace ---> configuration ---> Data connector blade .\n\n2. Search for 'Common Event Format (CEF) via AMA' data connector and open it.\n\n3. Check If there is no existing DCR configured to collect required facility of logs, Create a new DCR (Data Collection Rule)\n\n\t_Note:- It is recommended to install minimum 1.27 version of AMA agent [Learn more](https://learn.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal ) and ensure there is no duplicate DCR as it can cause log duplicacy_\n\n4. Run the command provided in the CEF via AMA data connector page to configure the CEF collector on the machine", - "instructions": [] + "description": "_Note:- CEF logs are collected only from Linux Agents_\n\n1. Navigate to Microsoft Sentinel workspace ---> configuration ---> Data connector blade .\n\n2. Search for 'Common Event Format (CEF) via AMA' data connector and open it.\n\n3. Check If there is no existing DCR configured to collect required facility of logs, Create a new DCR (Data Collection Rule)\n\n\t_Note:- It is recommended to install minimum 1.27 version of AMA agent [Learn more](https://learn.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal ) and ensure there is no duplicate DCR as it can cause log duplicacy_\n\n4. Run the command provided in the CEF via AMA data connector page to configure the CEF collector on the machine" }, { "title": "Step B. Configure Cortex Data Lake to forward logs to a Syslog Server using CEF", - "description": "[Follow the instructions](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-from-logging-service-to-syslog-server.html) to configure logs forwarding from Cortex Data Lake to a Syslog Server.", - "instructions": [] + "description": "[Follow the instructions](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-log-forwarding-app/forward-logs-from-logging-service-to-syslog-server.html) to configure logs forwarding from Cortex Data Lake to a Syslog Server." }, { "title": "Step C. Validate connection", @@ -3125,7 +3121,7 @@ "contentSchemaVersion": "3.0.0", "displayName": "PaloAltoCDL", "publisherDisplayName": "Microsoft Sentinel, Microsoft Corporation", - "descriptionHtml": "

Note: Please refer to the following before installing the solution:

\n

• Review the solution Release Notes

\n

• There may be known issues pertaining to this Solution, please refer to them before installing.

\n

The Palo Alto Networks CDL solution provides the capability to ingest CDL logs into Microsoft Sentinel.

\n
    \n
  1. PaloAltoCDL via AMA - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent here. Microsoft recommends using this Data Connector.

    \n
  2. \n
  3. PaloAltoCDL via Legacy Agent - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the legacy Log Analytics agent.

    \n
  4. \n
\n

NOTE: Microsoft recommends installation of PaloAltoCDL via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by Aug 31, 2024, and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost more details.

\n

Data Connectors: 2, Parsers: 1, Workbooks: 1, Analytic Rules: 10, Hunting Queries: 10

\n

Learn more about Microsoft Sentinel | Learn more about Solutions

\n", + "descriptionHtml": "

Note: Please refer to the following before installing the solution:

\n

• Review the solution Release Notes

\n

• There may be known issues pertaining to this Solution, please refer to them before installing.

\n

The Palo Alto Networks CDL solution provides the capability to ingest CDL logs into Microsoft Sentinel.

\n
    \n
  1. PaloAltoCDL via AMA - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent here. Microsoft recommends using this Data Connector.

    \n
  2. \n
  3. PaloAltoCDL via Legacy Agent - This data connector helps in ingesting PaloAltoCDL logs into your Log Analytics Workspace using the legacy Log Analytics agent.

    \n
  4. \n
\n

NOTE: Microsoft recommends installation of PaloAltoCDL via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by Aug 31, 2024, and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost more details.

\n

Data Connectors: 2, Parsers: 1, Workbooks: 1, Analytic Rules: 10, Hunting Queries: 10

\n

Learn more about Microsoft Sentinel | Learn more about Solutions

\n", "contentKind": "Solution", "contentProductId": "[variables('_solutioncontentProductId')]", "id": "[variables('_solutioncontentProductId')]",