Azure-Sentinel/Tools
v-rucdu 22e3e6e903
Solution Tool Updates for Template Spec Migration (#4655)
* Initial Template Spec Automation

* Example Template Spec Input File

* Updated code to add Template Spec for parser

* Updated Dataconnector meatdata id

* Handled Template Spec for AR, HQ and Workbooks

* 1PConnector support and techniques, id prop for HQ

* Handled the review scenarios

* Updated Package tool for comments from Sarath

* Tool updates

* Updated files

* Working Template with Analytical Rule Fix

* Updated ResourceId ref of Workbook, AR and HQ

* Fixed the solutionId issue

* Fixed AnalyticalRule typo

* Fixing query frequency, query period issue

* Updated code as per Roey's feedback

* Incorporated the feedback from Roey

* Changed ParserName

* Modified Template Spec Name

* Added missing status property for Analytics Rule

* Workbook Metadata and Analytic Rules Changes

* Update createSolution.ps1

* Update createSolution.ps1

* Fixed multiple workbook key issue

* Reverted parser updates

* Commiting changes for the workbooks and contentId fix

* Checking-in the Parser changes for template specs

* Changing the function alias of the parser object

* Content Types are referenced as varaibles across metadata dependencies and changed Parser content id

* Update createSolution.ps1

* Template Spec V2 Tooling Changes

* upated analytical rule version to 2.0.0

* read the version property from input file

* Copied code to the V2 folder

* Handled UIdefinition changes in templating file

* Deleted unwanted files

* Deleted unwanted files

* Removed preview keyword

* IsPreview flag for data connector has been handled

* Workbook UI Parameter Block commented

* Removing workbook name from UI

* Versioning change for the content types

* Added the logic for the existing function apps title

* Function App existing code modified Logic

* adding the description validation check

* Workbook Versioning change

* ISV email property handling in the tool

* Playbook TemplateSpec code changes

* Updated correct content for Playbooks

* Fixed JSON Validation issues

* Added missing metadata prop

* Added new template spec name code changes

* Update Metadata Path

* Added resource property for DC content changes

* Added customConnectorCount, Removed Junk Resource

* Fixed the locale issue in documentation links

* Added ReadMe file and Resolve review comments (#5115)

* Added ReadMe file and Resolve review comments

* Fixed PR validation issue

Co-authored-by: Eli Forbes <v-eliforbes@microsoft.com>
Co-authored-by: v-sabiraj <v-sabiraj@microsoft.com>
Co-authored-by: Sarath Tirumalareddy <tichandr@microsoft.com>
Co-authored-by: Sapan Goel <95875056+ms-sapangoel@users.noreply.github.com>
Co-authored-by: ashishsyal <89064706+ashishsyal@users.noreply.github.com>
2022-05-26 10:55:44 +05:30
..
ARM-Templates Updated README with better explanation 2021-07-27 12:49:26 +02:00
Archive-Log-Tool Deleted Prerequisites 2022-03-09 22:13:09 -08:00
Az.SecurityInsights-Samples Update README.md 2021-06-21 22:44:57 -07:00
AzureDataExplorer Revert "Revert "Merge branch 'master' of https://github.com/Azure/Azure-Sentinel"" 2022-01-03 16:21:46 +02:00
AzureSentinel-DevOps-Board-Template Update Readme for S3-Lamda & reorganize Tools 2020-08-08 00:00:17 -07:00
ConvertYamlToJson code cleanup and comments 2022-03-16 23:16:07 +01:00
Create-Azure-Sentinel-Solution Solution Tool Updates for Template Spec Migration (#4655) 2022-05-26 10:55:44 +05:30
CustomLogsIngestion-DCE-DCR Solution Tool Updates for Template Spec Migration (#4655) 2022-05-26 10:55:44 +05:30
IntrotoKQL Revert "Revert "Merge branch 'master' of https://github.com/rons4/Azure-Sentinel"" 2022-01-03 11:27:36 +01:00
M365-PowerBi Dashboard M365D tutorials and tools (#3186) 2022-01-19 11:29:05 -08:00
MITREATT&CK-LayerGeneration-Notebook updating KQL in readme 2022-05-24 14:20:58 -07:00
ParameterizedFunction Added files 2020-09-30 08:50:48 +10:00
Playbook-ARM-Template-Generator updated Playbook ARM Template Generator Readme 2022-05-10 08:18:09 -07:00
PowerShell Added PowerShell that creates alert rules from rule templates for all configured data sources 2021-02-14 16:59:02 +01:00
RDAP/RDAPQuery Merge pull request #4841 from FlyingBlueMonkey/patch-4 2022-05-09 13:33:06 -07:00
RuleMigration Localization links fixed 2021-03-15 10:32:20 +03:00
SIEM-Data-Migration link locale fix 2022-05-06 15:07:16 +02:00
Sample Code updating logic to new fields OperationNameValue 2021-09-17 18:18:33 -07:00
Sample-Data-Ingest-Tool Update ReadMe.md 2022-03-10 17:11:53 -08:00
Sentinel-All-In-One Updated README 2021-09-15 18:02:45 -07:00
Simulators Delete WriteToLA - AIPMassDowngrade.ps1.csv 2021-09-30 15:28:14 -05:00
Transformations-Library Merge pull request #5023 from javiersoriano/patch-10 2022-05-23 14:42:10 -07:00
UploadToBlobLookupTables Updating Deploy buttons and links part 2 2021-06-16 01:40:49 +00:00
dashboard Delete Sentinel_Hunting_Notebook.pbix 2020-09-17 10:27:24 -07:00
externaldata fixed urls 2021-09-26 22:41:59 -04:00
stats updated latest content 2022-05-05 14:59:26 +05:30
ReadMe.md branding changes 2021-11-29 10:58:59 -08:00

ReadMe.md

About

This folder tracks Microsoft Sentinel API integrations, tools and deployment templates that can enable you to easily:

  • connect your solutions with Microsoft Sentinel
  • deploy in Microsoft Sentinel
  • migrate to Microsoft Sentinel
  • work easily and connect to different products in Microsoft Sentinel

Here's an inventory of Microsoft Sentinel tools.

Azure Sentinel Tools and Templates

  • Azure-Sentinel2Go - Expedites deployment of Microsoft Sentinel lab with pre-recorded datasets

Microsoft Sentinel Integrations