Azure-Sentinel/Parsers/ASim Sysmon for Linux
Ofer Shezaf 9b8247c42e Rename product 2021-11-03 10:40:18 +02:00
..
README.md Rename product 2021-11-03 10:40:18 +02:00
SysmonForLinuxFullDeployment.json Update SysmonForLinuxFullDeployment.json 2021-09-30 15:05:49 +03:00

README.md

ASIM parsers for Sysmon for Linux

This template deploys all the upcoming Sysmon for Linux Microsoft Sentinel ASIM parsers. The template is part of the Advanced SIEM Information Model (ASIM). The Advanced SIEM Information Model (ASIM) enables you to use and create source-agnostic content, simplifying your analysis of the data in your Microsoft Sentinel workspace.

When deploying the parsers, you make sure that telemetry from Sysmon for Linux is analyzed using the built-in Microsoft Sentinel Analytics. You also enable analysts easier access to the telemetry using a known, standard, schema.

Note: to get the best value from ASIM and make sure that Sysmon for Linux telemetry is included in Microsoft Sentinel Analytics, deploy the full ASIM parser suite.


Deploy to Microsoft Sentinel


The template deploys the following:

  • ASIM Sysmon for Linux File Activity parsers - vimFileEventLinuxSysmonFileCreated, vimFileEventLinuxSysmonFileDeleted
  • ASIM Sysmon for Linux Process Events parser - vimProcessCreateLinuxSysmon, vimProcessTerminateLinuxSysmon
  • ASIM Sysmon for Linux Network Sessions parser - vimNetworkSessionLinuxSysmon