This commit is contained in:
v-amolpatil 2024-08-13 11:37:30 +05:30
Родитель a1920abe07
Коммит fc8ea67f4c
28 изменённых файлов: 988 добавлений и 954 удалений

Просмотреть файл

@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
@ -27,5 +30,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: UrlCustomEntity
version: 1.0.0
version: 1.0.1
kind: Scheduled

Просмотреть файл

@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
@ -27,5 +30,5 @@ entityMappings:
fieldMappings:
- identifier: Name
columnName: MalwareCustomEntity
version: 1.0.0
version: 1.0.1
kind: Scheduled

Просмотреть файл

@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
@ -29,5 +32,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.0
version: 1.0.1
kind: Scheduled

Просмотреть файл

@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- ApacheHTTPServer_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
@ -31,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.0
version: 1.0.1
kind: Scheduled

Просмотреть файл

@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
@ -31,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.0
version: 1.0.1
kind: Scheduled

Просмотреть файл

@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
@ -40,5 +43,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: UrlCustomEntity
version: 1.0.0
version: 1.0.1
kind: Scheduled

Просмотреть файл

@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
@ -31,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.0
version: 1.0.1
kind: Scheduled

Просмотреть файл

@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
@ -31,5 +34,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: UrlCustomEntity
version: 1.0.0
version: 1.0.1
kind: Scheduled

Просмотреть файл

@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
@ -26,5 +29,5 @@ entityMappings:
fieldMappings:
- identifier: Url
columnName: UrlCustomEntity
version: 1.0.0
version: 1.0.1
kind: Scheduled

Просмотреть файл

@ -8,6 +8,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
@ -42,5 +45,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.0
version: 1.0.1
kind: Scheduled

Просмотреть файл

@ -1,6 +1,6 @@
{
"id": "ApacheTomcat",
"title": "Apache Tomcat",
"title": "[Deprecated] Apache Tomcat",
"publisher": "Apache",
"descriptionMarkdown": "The Apache Tomcat solution provides the capability to ingest [Apache Tomcat](http://tomcat.apache.org/) events into Microsoft Sentinel. Refer to [Apache Tomcat documentation](http://tomcat.apache.org/tomcat-10.0-doc/logging.html) for more information.",
"additionalRequirementBanner": "These queries are dependent on a parser based on a Kusto Function deployed as part of the solution.",

Просмотреть файл

@ -2,16 +2,16 @@
"Name": "Tomcat",
"Author": "Microsoft - support@microsoft.com",
"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\" width=\"75px\" height=\"75px\">",
"Description": "The Apache Tomcat solution provides the capability to ingest [Apache Tomcat](http://tomcat.apache.org/) events into Microsoft Sentinel. Refer to [Apache Tomcat documentation](http://tomcat.apache.org/tomcat-10.0-doc/logging.html) for more information.\r\n \r\n**Underlying Microsoft Technologies used:** \r\n \r\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n \r\na. [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api)",
"Description": "The Apache Tomcat solution provides the capability to ingest [Apache Tomcat](http://tomcat.apache.org/) events into Microsoft Sentinel. Refer to [Apache Tomcat documentation](http://tomcat.apache.org/tomcat-10.0-doc/logging.html) for more information.\n\n This solution is dependent on the Custom logs via AMA connector to collect the logs. The Custom logs solution will be installed as part of this solution installation. \n\n **NOTE**: Microsoft recommends installation of Custom logs via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024**. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/azure/sentinel/ama-migrate?WT.mc_id=Portal-fx).",
"Data Connectors": [
"Data Connectors/Connector_Tomcat_agent.json"
],
"Parsers": [
"Parsers/TomcatEvent.txt"
"Parsers/TomcatEvent.yaml"
],
"Workbooks": [
"Workbooks/Tomcat.json"
],
],
"Analytic Rules": [
"Analytic Rules/TomcatCommandsinRequest.yaml",
"Analytic Rules/TomcatKnownMaliciousUserAgent.yaml",
@ -37,9 +37,11 @@
"Hunting Queries/TomcatUncommonUAsWithClientErrors.yaml",
"Hunting Queries/TomcatUncommonUAsWithServerErrors.yaml"
],
"dependentDomainSolutionIds": [
"azuresentinel.azure-sentinel-solution-customlogsviaama"
],
"BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Tomcat",
"Version": "2.0.1",
"Version": "3.0.0",
"Metadata": "SolutionMetadata.json",
"TemplateSpec": true,
"Is1PConnector": false
"TemplateSpec": true
}

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- InitialAccess
relevantTechniques:

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- Exfiltration
- Collection

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- DefenseEvasion
relevantTechniques:

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- InitialAccess
relevantTechniques:

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- InitialAccess
relevantTechniques:

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- InitialAccess
relevantTechniques:

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- Impact
- InitialAccess

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- Impact
- InitialAccess

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- InitialAccess
relevantTechniques:

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- InitialAccess
relevantTechniques:

Просмотреть файл

@ -7,6 +7,9 @@ requiredDataConnectors:
- connectorId: ApacheTomcat
dataTypes:
- TomcatEvent
- connectorId: CustomLogsAma
datatypes:
- Tomcat_CL
tactics:
- InitialAccess
relevantTechniques:

Двоичные данные
Solutions/Tomcat/Package/3.0.0.zip Normal file

Двоичный файл не отображается.

Просмотреть файл

@ -6,7 +6,7 @@
"config": {
"isWizard": false,
"basics": {
"description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\" width=\"75px\" height=\"75px\">\n\n**Note:** _There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing._\n\nThe Apache Tomcat solution provides the capability to ingest [Apache Tomcat](http://tomcat.apache.org/) events into Microsoft Sentinel. Refer to [Apache Tomcat documentation](http://tomcat.apache.org/tomcat-10.0-doc/logging.html) for more information.\r\n \r\n**Underlying Microsoft Technologies used:** \r\n \r\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n \r\na. [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api)\n\n**Data Connectors:** 1, **Parsers:** 1, **Workbooks:** 1, **Analytic Rules:** 10, **Hunting Queries:** 11\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)",
"description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Tomcat/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe Apache Tomcat solution provides the capability to ingest [Apache Tomcat](http://tomcat.apache.org/) events into Microsoft Sentinel. Refer to [Apache Tomcat documentation](http://tomcat.apache.org/tomcat-10.0-doc/logging.html) for more information.\n\n This solution is dependent on the Custom logs via AMA connector to collect the logs. The Custom logs solution will be installed as part of this solution installation. \n\n **NOTE**: Microsoft recommends installation of Custom logs via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024**. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/azure/sentinel/ama-migrate?WT.mc_id=Portal-fx).\n\n**Data Connectors:** 1, **Parsers:** 1, **Workbooks:** 1, **Analytic Rules:** 10, **Hunting Queries:** 11\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)",
"subscription": {
"resourceProviders": [
"Microsoft.OperationsManagement/solutions",
@ -60,14 +60,14 @@
"name": "dataconnectors1-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "The solution installs the data connector ingesting Apache Tomcat internal logging and web application logging will remain independent. After installing the solution, configure and enable this data connector by following guidance in Manage solution view."
"text": "This Solution installs the data connector for Tomcat. You can get Tomcat custom log data in your Microsoft Sentinel workspace. After installing the solution, configure and enable this data connector by following guidance in Manage solution view."
}
},
{
"name": "dataconnectors-parser-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "The solution installs a parser that transforms ingested data. The transformed logs can be accessed using the TomcatEvent Kusto Function alias."
"text": "The Solution installs a parser that transforms the ingested data into Microsoft Sentinel normalized format. The normalized format enables better correlation of different types of data from different data sources to drive end-to-end outcomes seamlessly in security monitoring, hunting, incident investigation and response scenarios in Microsoft Sentinel."
}
},
{
@ -323,7 +323,7 @@
"name": "huntingquery1-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query shows request to forbidden files. This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query shows request to forbidden files. This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]
@ -337,7 +337,7 @@
"name": "huntingquery2-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query shows abnormal request size. This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query shows abnormal request size. This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]
@ -351,7 +351,7 @@
"name": "huntingquery3-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query shows errors events. This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query shows errors events. This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]
@ -365,7 +365,7 @@
"name": "huntingquery4-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query shows rare files requested This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query shows rare files requested This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]
@ -379,7 +379,7 @@
"name": "huntingquery5-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query shows rare URLs requested. This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query shows rare URLs requested. This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]
@ -393,7 +393,7 @@
"name": "huntingquery6-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query shows list of files with error requests. This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query shows list of files with error requests. This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]
@ -407,7 +407,7 @@
"name": "huntingquery7-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query shows URLs list with client errors. This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query shows URLs list with client errors. This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]
@ -421,7 +421,7 @@
"name": "huntingquery8-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query shows URLs list with server errors. This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query shows URLs list with server errors. This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]
@ -435,7 +435,7 @@
"name": "huntingquery9-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query searches uncommon user agent strings. This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query searches uncommon user agent strings. This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]
@ -449,7 +449,7 @@
"name": "huntingquery10-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query shows rare user agent strings with client errors This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query shows rare user agent strings with client errors This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]
@ -463,7 +463,7 @@
"name": "huntingquery11-text",
"type": "Microsoft.Common.TextBlock",
"options": {
"text": "Query shows rare user agent strings with server errors This hunting query depends on ApacheTomcat data connector (TomcatEvent Parser or Table)"
"text": "Query shows rare user agent strings with server errors This hunting query depends on ApacheTomcat CustomLogsAma data connector (TomcatEvent Tomcat_CL Parser or Table)"
}
}
]

Разница между файлами не показана из-за своего большого размера Загрузить разницу

Просмотреть файл

@ -0,0 +1,32 @@
{
"location": {
"type": "string",
"minLength": 1,
"defaultValue": "[resourceGroup().location]",
"metadata": {
"description": "Not used, but needed to pass arm-ttk test `Location-Should-Not-Be-Hardcoded`. We instead use the `workspace-location` which is derived from the LA workspace"
}
},
"workspace-location": {
"type": "string",
"defaultValue": "",
"metadata": {
"description": "[concat('Region to deploy solution resources -- separate from location selection',parameters('location'))]"
}
},
"workspace": {
"defaultValue": "",
"type": "string",
"metadata": {
"description": "Workspace name for Log Analytics where Microsoft Sentinel is setup"
}
},
"workbook1-name": {
"type": "string",
"defaultValue": "ApacheTomcat",
"minLength": 1,
"metadata": {
"description": "Name for the workbook"
}
}
}

Просмотреть файл

@ -0,0 +1,3 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|-------------------------------------------------------------------------------------|
| 3.0.0 | 13-08-2024 | Deprecating data connectors |