71f13168a9
In current ASIM common fields and NetworkSession schemas EventSeverity is listed as a Recommended field. Change its class from Mandatory to Recommended. https://learn.microsoft.com/en-us/azure/sentinel/normalization-common-fields https://learn.microsoft.com/en-us/azure/sentinel/normalization-schema-network |
||
---|---|---|
.. | ||
deploy | ||
dev | ||
lib | ||
schemas | ||
ASimFullDeployment.json | ||
README.md |
README.md
Deploy ASIM
This template deploys all ASIM parsers. The Advanced Security Information Model (ASIM) enables you to use and create source-agnostic content, simplifying your analysis of the data in your Microsoft Sentinel workspace.
For more information, see Normalization and the Advanced Security Information Model (ASIM)
To deploy a single schema use the buttons below:
ASim Schema | Deploy | Deploy to Azure Gov |
---|---|---|
Audit Event | ||
Authentication | ||
Dns | ||
File Event | ||
Network Session | ||
Web Session | ||
Process Event | ||
Registry |