From 7a43acec8c85ad50509a4187bdb4f690e0ed7873 Mon Sep 17 00:00:00 2001 From: PrasadBoke Date: Tue, 10 Dec 2024 16:01:46 +0530 Subject: [PATCH] Solution packaged --- Solutions/Doppel/Data/Solution_Doppel.json | 4 +-- Solutions/Doppel/Package/3.0.0.zip | Bin 8740 -> 8627 bytes .../Doppel/Package/createUiDefinition.json | 2 +- Solutions/Doppel/Package/mainTemplate.json | 28 +++++++----------- 4 files changed, 13 insertions(+), 21 deletions(-) diff --git a/Solutions/Doppel/Data/Solution_Doppel.json b/Solutions/Doppel/Data/Solution_Doppel.json index 6d1a4ca731..e366a648cc 100644 --- a/Solutions/Doppel/Data/Solution_Doppel.json +++ b/Solutions/Doppel/Data/Solution_Doppel.json @@ -2,9 +2,9 @@ "Name": "Doppel", "Author": "Doppel", "Logo": "", - "Description": "The Doppel Integration for Microsoft Sentinel streamlines the ingestion of Doppel security events and alerts through a custom data connector, converting raw event logs into a compatible format for use in workbooks. This enhances digital risk visibility by enabling users to monitor threats, analyze alerts by category, and gain actionable insights.\n\n", + "Description": "The Doppel Integration for Microsoft Sentinel streamlines the ingestion of Doppel security events and alerts through a custom data connector, converting raw event logs into a compatible format for use in Workbooks. This enhances digital risk visibility by enabling users to monitor threats, analyze alerts by category, and gain actionable insights.\n\n", "Workbooks": ["Workbooks/Doppel.json"], - "Data Connectors": ["DataConnectors/Connector_Doppel.json"], + "Data Connectors": ["Data Connectors/Connector_Doppel.json"], "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Doppel", "Version": "3.0.0", "Metadata": "SolutionMetadata.json", diff --git a/Solutions/Doppel/Package/3.0.0.zip b/Solutions/Doppel/Package/3.0.0.zip index 795e2d3cf3ce39e9608661dd9b8152915b4c48eb..37edaaba077812e83e1f00fa88c82bccc83781ea 100644 GIT binary patch delta 7945 zcmYkBWl)^KwrB_U;5N8RfWZj?g1Zw47TkgpTmm2N?(XgoG`PbA3Be(_yE9ne<=l6x z?%7?t`$zY#>gpe>y7nrT`YuVLrig$@07CsY*!&}PLH`>RDG4Oxz&8>dtN)}5fsU1% zCk6-(@ju)DGo6aqx~#|~uD9B}4v@o~liR+@xjVO7>DOw}kNk`@Qe=@g(5*B_#gwlW z1NDK5GX}LD$h6&HyMB6pV{TIjBp`$fnlbm5@?t!+^uxomLzq&M=<6kRaMMeQ5D$M@ zjchTWB9Is^3dYJ*J>Hb@TKY0&S9yH9*f_Ws^^whk#m1s=L_Ir&Y;!CL zUs?A*zHXRYlzq}>+XxniKkv5Sg7t$I1kb28MUVbwGt8EtnO^XG@R#LPwls;BoEl&@ z?Ive2p7=@;TgM?Gstlr)pRF{<8ax@zr;B{ZTey3CvG|+9hyBw@VqusZq zaw3ghHeba_!(!!-7CjS;7~MY3ATLJ?6)d>yOrsYNd#5^z4Vk6wiqcJgbigjX>o)J| z0j3w-B+~CB^Wx7*F5z=Ik7zX$$4MScNQVW43*Q`D^8(aAGxo>BMITcY&mg+ z_Pk?Q3Qiq<>U!SoTFYe}ow(Px+?hY|#*je9plp)0W0j(%*I-3k&?tn3CK<*#g=z%Q z2HjYjZ#GPkKi8~Il10yoVTTlbW7Wj6Cxs|!2Y~g zTGF~D31!o@!0EuarTI!hz2KzM7mL9R-eyVIyRynoge7A>RvtY`SbmPYB0%Eg_+If| z4152SgG;T3gQcmcGyD#f7}q6!Wu&wv^L=WC>Qns+<&NiPPNtYH^OVh*v)Zgx{aBw< z2e7ATsS@-sAmASMXgaFY2p3(r4Vs!5mgnJSun0JJg{qMa zLl?RuBn8~K2MGu8ya&*;IfrVVhHx8eSM4Dq_Lmq5fBo3&g+_A~XSy@({+#VBra7(-u4i%w5#9kxcfQ|Yu z>O~=vi09Fg!`|BO{PKDZwDJbO9e%aJe`4TKll`VHT;n>|P#VERHI&_^k|bDR)oVgQ zcpKV@ddktXK;Ik)A(RF}n+9ym0L_OZCXwY8YbWj+#$+0w-zNeivrq4w;<)PogOTL^`UrNtU2h zxIw%r%=h+vb}TZCija)mr4xxW3KpqcZp~7|e2Q4s2v5cGgGXD9ef21W9EcOLn z--^^mwW@J}A)+%|+&O)$sF6Ecjr(#*2zybC9L&Z{%t8{#aLswqTNxB^iWk|=go4WJ zBptXnsKhwG89b;1=<0Y1mwZSd#Vz>oC4zi{s8@Y-x(FvPpVl(~^ffY3;ezW{-vWM3 z`>vTE`;P{+f||kiNaGBJ!Rvi)SVHo|kDV zczIIa4fE|3Pdepg2Agr16=W0=Ty`y3{!5h_(*#V95@y~>d-@ZnB`G`duOkKyc_=8D z?w;=wrxz{D@YbDRu*?E0wFUf~LYBy_#{-8>k@UhH=bA8OzQsWs23#ntM0ArtL6 z3|9TXZKx;se9pwBq=bTG`4Q(^*rORZ?I9xEw(~r@Mq9fNQrUS8OE&QjdVw!SmSE4Q zkVClN1eFQDPb2+d>iVfP?K6R5#jJeiLi-GX#I!4$MhRO8Nw!SFdBsP89F-f_#c>of zQF3hRiokr0U2Wak=`@qIr>c9_dgQdIey$3U7hYRv$#b!$do6}ZN_DMNYQa18nA#|8 zXx|-U`~0v)G@J4g^^%uAAErJjT~?xnqlX4SIu2ddxw$ma$EFUtKu@9HR+9E-Cu+qU zpD$w?3O=b5wf$xEeNO&TYM<+J!1_LApGV13WtN4&NQnv`0XkNeGb2KzSZKYmUr0R& zFQjB*w>P$CnIxk~g#XGA|8IM=c~52=lIXQr1}oPH*yz?gOmc8rPr+v$X*@o*0w zw~MP|*KeK7$^yXG%FsUk2=w~}EcD8e+2nvK6uO0$r8>6V`F{48OfOr))oh@sEp z+)Z0(JfVZ+lL+h>x#NcqR-=Uo#djJVK_NEDD+ewQ3_#6gxLW8kPU*DO@`0 zdy0uOpwg^9v*I{}XoB$9DbnFwj|f{XbAqZ z<7`*)az50w@zf&&Dm?gS@E0Hu%`=+WTTEDDw!Y0{*&b>Dwr0Ln1h2PkYUD69Hd;!8 z1yw{uY4WF1qbeT$+Ghwsd4G>GYaNV_JuH3bSls!r#HfvGhV%D*bD^K83Ey9L=;WCzK&iiWXAXq8dvm|S`5jL zvBVi4sYv*T@bkD7#mv#<(#6=Ebb2h)O1WYzfwZ6DV(p#}&4TV6<7*6hC=>8V(~2LG zI;tM#aKKM?(5sC_9Dsp^8jD9=7-usjWY}KfI8!(&P|>*6SZ)lz`%O9?QG6$IrC-xW zDL)!dfk^UoIBQ)IOX9{r_Fx62UT?6&soa>vL@J?5B1C;!bu_zMsMjdu772DjiRW9p zcS${nN~;@z8|KkV#NfRKfAe@kODh)7z_zyw)EB2fy z_IuS$45CTG`+i;Rlo?0$2ZhNxP^i`{F~8Ui*!{@QRUOI29WlW?X!*b1-;!eM%s|n;VoDJ-;?IRhjGW!RK8uP(qOjKEVHD?4h43T$@Scmh4 z--%YRsrjxlzVdt)-|uffeeRu#CZ}?5yGgM+Xgf&fXU9*o zu8m9-QghF(G6o19V(qg+QhTA^_qj0@RpLzfNerHOXdJ^GYJvk^hC)h(H8UnM0{5MObH2X)e5fmHo9?b@v8!G# z6`7vFBB6ao=0m=5TJUz8>U)Zd%HN5d&FLNCD!PWM#`kTSs_#x*DGiW7onef>+Hv!f zfmRo^+~I=GVDAK#vL6a%lEr@$Ss96>X<5qe@De+}8nIunZ7`1+D~0TbG<`+4?Ukcx z;}x@IIRiyJ_D4JGsHAIJE16J8w!s}}U4R6gLPwr9#>d|3Od7kYEY(wbxs|RTx@x`U zt0k32ihNfcEv@zSl>kE=b=)ecSOA}a5-?7YFWsTTJa+x}0^BBU@4XkbzdZMAg1h7o zo;LAL9|z64e=_X7tDfmIM))G0ES~vgO*jU>&mbOQKJTt$r`70HRu_qSYJ=bFcYOLhw46FKz=XK`9Nq69rT*y<3N5a=jc?&u;510S0FLWKjGkhI`j4)ODRb_S`X&Mp?A?gzy z@II45 z*%c*h0iHcDYc%Ekz~;y-HkGC!#3deSP5ri<@T zaUkf1RC_!=mVJ2lTU0;eWk$HW!-j9jPMe(@U0qe;l)>Q~MS+Iyps};_Muzk~J6YX9 ze-?TQT1q^DRiR!1#qbQRF|BrxP5<}LXBH)E+Ej|-GA!jhI+5RTQH+Wr4G!Q_dF8l8 z2B2S|R@{tZY#n{F=1I~(?OW!c9F=BH4E%4bbWX+a@aE2(!oFT@86r%+Rno*7l{@-E zm}(f&-CD+R^)BL*UkT}P1m4gIJBft_El7lfl5HfH*~Eig+enV9kh;;RxhC36G-Bzc zx}3OIILtS0$VHVH&JtM~t1yr$KOvFr7j7t%G^L1^s8dcs4 zE{+3<7dYhRWcknv=sn?~&PJ0B(>9%#=T?o=A)ipVr;DFB33$l_s)Ov%8#dC zoc46GV~rtLcq5o_YmXetGfyrJo4%NQkVB3g4tUNpM>WlsvJD_DZVU;f8Rb2AY<^{bJO`)h%fxBXAg2o z%vqf$a=+E5?$;TuiWHJopdClBFjxP(^6VPi;sGNzHVx}jDg9qvr%*l68i|_V>Jhv$*TRV2AN=6 zL48fA;m#;30?ubtoLDiolFT%DfvB$}s7eHqGG6G#s}a9X&=q@ktfZgth=b)HQXg}p zCP!$2=sPj(;J3;z7a&E-MrvL5910>yjxoXpJ(?7~+0n!gM^bY{(bma~1s1fg#kHL6 zM`r<*E562LoSKJBGbyrjE({6+S}Lb@h`Aq?U^FPwAJj&3!^GWzA!aT40QM9WP0fU~ zH)@{Iol9($vzh6e?e*MUn}Q^np=c5_I~(eNg;V<^BIBy`q?(cDXFFMn)g!LpiZhcF zZ@5My&d*jWjpa$#yYO)x$@m26+-Y*At`UYDABU&LF5j}{J3y=(sK!=cw8BVM5OfBU zPsUc2rUk9y4;n}cMB+}JY%`W%_797Y1#5$CqCJd{Xo8|;>V5bH5ijPW)y5gp^#d+| z*DJKR+W+kwDggpz^AGwRxm3|qYrGS|HPaPdlOpxwoDFxC9-V=DXYM#n#VY!btZJCUj1=dK!@q69j=}!=CeuJj<5FkWMiBc zC;+5i+0V0sOCRB)J~rbq)_67Ny)q{Z9mT#^Mo7;aJaBl+!U|ixxu|I3 zoL`ffD*f{n!>pjWxI3=lO5VQp#FCA-)%V8swDm7_2fX#I2<@@xK^uRtv+Zfj(=CO;1QlAlxc-7W0BYgm z_CE6E_0%#rQi(Ch%g3m3e6c~cuy0*%N2qC0J1+&GP9kGd8DWo|2u)N_eK!#=Sc*|&EpSAMI-sX5^ z=FZ+a&sl#tGqlmhwA%t<=`O|$(C3XNlsrwGo%2wg6WFOePJMi5prLGDdk9n|{xIlS zY4LSXF6W2g&B1W^U~f_$>&bjV_>XWKQ&rE(nGSNj1Kf|`mg}R;vd&^|yFS?Ze4D?$ z)BJvpp5C$C%hx4D)na9}Vwm%^xauY%c+5(-8|eCRD#jlFynDoQUEk~ws991fa#)wV zuDF{_E@|mosdjADIrbNofQ%!HaJnPZOHTci>Ea-}ZL^zO`91sB4ZDl&i89p}`)7BU z#ri{nFdx%d(+|HMb_PK24N31v6c^6bo8 z`A&rKi89GIZmjDj{g1{7a9*EgzAo8#PO}7yKk<>nTrmesUdijQRQ4*nX!K#hycD-} zul^_YXCbRES!g#X2j}jCVhmF(Pp1d0GWaFP)KoyubogeW*MjAbn1&z;R{(or?~@Cx@>WxXW@|bL z&R0+DP$PMI&o!iEoRx#MZ*G0Jv|&#`ybV)$^5ZjqSJ@VX_H~f(;vP}aSGN|4NZM?f zK|Lk!nw9K{G&2oocO=~#mcIWMbs14VtgqBS{x$-n4)dWudwj}ALaB&GM6(e-ny z@hq#0>fumB^XHYDxc(_4+;K%TN!N=bl85;PvGky~ciGZtZz0Vg9Esuen(H(Wr zEN*>6JJ0LN6!%ejQ|7A(8whp3wDy#y5r@P1*4{>xOBoSR`n^8LGyq~#!S`AhZ!`Z} z5-yn3d_oM7b(X}6?U2HTmU9~I=N}czX^J&52P}5>3Pp-xzCYxmRMTqxC^rMS4b%l? z$d{45=fB8k+|m0r8$E4af3(8Ni?OA&ZRcz$|SQ$#^UjqN?f)-VzQahB-~r?F=5`}nUq}2wQaD@&R*sO03@QG0Q<-I-JL;Oxiqb^2 zCgx)clw84$m&|=Y*-@g!Ca06C=nHf8URNnfZ z0QQ+f;YgpHzWHN6+XFtV&R}?hEX{9@H$mf>rLHS!#(z^`O#TZ4rLL{C=xVQWIXz4DT_l%-ER6K#!-eGQZJel?U^- zUu}ZouNO!Ys2LXhFknq|G}?(YdC-nYhl4z+w^RI7?Qa1u*zi1dHaJ(&mq35{VNWF~};uIB3wE_W?mpg&C+<5qfAyFncnD zy&(VYQnfBxvICg`sCjy7YkS_7WvNs~$Eh98;F2&6_WtG4GY2^IQP$N}04cGiw4K5i zb~=HRk^bUvtUCDMKT>U!{Z7vEQoat{-Q@2#^0xhp*T_#|E65~~RgZ3VPG0Xu#mVrL z#aCDe+P4x6Uf|CT^xz16+n&1SUXK|sPe!t&zHyG#mU&Jnk7_)ePL?X4dLV){W<5tU zk_Fnqp@oenBDGi-j5thh8TfrBgszdQO#*f7r(j`tkbYZvr+ zz`{}hzq;?;@bPBeQE-dK>FQ(+u9L&_97=88`pf8X0k-O{SJrcb-v|w=3zO0l($@*U zCutGX(K?RZtd!xG|LdQynCOEOVtk}TO`lR{iERShiGQG^f4W`T6E|qy#&-uRqYQXb zH+>Su7x?XEo0}qaWbF{cxN0Jq*K+c0a}Y%!Q$Y538~Jz72y+{i{j?SjpKMX^>@+Fd zMS&JFGO)m zhx@(xku+5=o$~@%-sFa?E1@icpM z=((NVa$&14W3}|!t-GlH9d&rz>0yxF`mLsP^ZFmZ{*3kn-q*s-oBKIQ`&20-O$6#J^p@Vd@oqg_-YUrTgq?;&pgC+&VA6<6}DY1O@mAak{Vq4u#q`Fn+c=gN} z5-9ecN8QsE-z-T2xu=GH=-zjX6h#G(MBol1CgCu(8<_pvu&4j|zI>CZ?seHzs>IrY zi7Sw7{H&K^}Z@7ALOce)t2??95&z~K@g zR%{lp|G8k`%~bHfWyjw!l<1Z3dm97(T(SsL{R4K?jXf*ztEp{{Z&C%ZWkM|Ld|rpq2nh XQc%*=zkcw4K{x4zh8lV4e-8aWwLC1{ delta 8059 zcmYkBWl)^kvOtmG?hNi8+-2~=-3jjQ5d6d4A!G<1Ttgs0u)!@za7l0o?h+i{J@37$ zd%A0P|LEO+S9R5Dk}Z`Z)l@-zLkNfZpS+5WF@pR5kcOs{QUE%u+V=mv^%ZSuH-B@=d9f$?5}r2H?PdSN?%PEi zf4L_hzL)wCa=C_PzvOZ{ z3%z;i?cdNyPBH93izF=w8KXOmhOhUY5gP*Lu0V-ZD%JxV_D^u&&r0H0^b~=3lY8SI z>5*zd_5Byqw)@OHQVd^>KP2_XRiX*MLhkh{61k zT=qP&FMUvkyf#W+Wh;E{UEYrav^hGHXvub~!Z5_X0M$_cV&Vfc_5OkP9o)^2j7Pvr zGNhiM?;CYsRPb;d$vISuq&UO>#|X|Ccl);YVM9IS3Z*eGa5Bq3?>omOal?)8m)G#TQpARU7N0g{ZqcGQ_81@fTsC&Qw<;}WryrXb(t%DM)&MdIvg%h<11ZWT2t6V&62n9 zF=HZWz=4R?NWZ5lr?h8h*!}meyus1V>?|$PwR|7EYqxhSH)+8YQgsI9ST{1W3A|Mo z9C%g^uMrR`%KLHMm$PQg&Ws(RI@O1j1|uB4L?rs_u<*p6COoEOqnrjVr-uNKX)8i| zUU0sZ|J-;1|GTOQ#a3BM?~G4VGjZOIPAI2J5Is+nnO-Mdr*FuoT6`a}*Jw7@Y{;%) zRFk=sRz=2U+71eycqe$Ad*jk>h0tG4hlbVQ3H^%YpXc9g)bRr@*aj<>jf6TnD13AC z8O}php;@!^h!4`h0c&K^5xW6QvSk@Dt|NMck#aj3FQ^~%T%x{NC+ zyZIv%`s#oZo&jd!0p*xyA7Sex$?!{t6!g6lEBP>PJ+aSn5)rwTg9R!c{G} zzSKL$ZYAPZ3QKLbb(QiE2h8l~-Jf{{($Vrh`BG zajkz~2KhQHU2Y(H!|tk?eP=9$k|~Kyw;3eKb1TE!a&e_5>v*KLJ&i@|P8x9#>D}$< z<3>isA`q*v$c>AHA1V=^`T@Du{9L3O3Vo*dMqVQzqX=w%6wXSb6EFAd1D#1dV2_0l z9-^*Il+`duf&AOkIo@v|f4x}p7PqN=V?i30J0vCrS4HS-7CteU%KJn`e8GqI^q>I1 zF_c}0XC~`!#q&EFRPwABcGGm@7L3~!$w-ECM=9Y_H;*{Te=?wTVHP2HTqmRv#)L;5 zK6gGIgaI;Rq)d>(wIsBgpqd6Rf&(}+x}ewRyQ^-B?Vn=FvmY3ci=AqU!R?MVAVX*y z-j`#@K%cfpSK$CR4<#W~P3oNTFx5eKhncSaVomIwyIX|0Zou9dT0b1hGm;`!lrgVP zIyM!B0f9>FQxFP4fdi8(cCfPihs3tKpz_{{Y#_{KotIm9ZOPiL-C0QbW{3#+wf?XA z_6u#xnGu}$yU}Mc2}U)BIrARaoXdb_^0EUxdL&>#UhD~Ulc)16YZ`kwHHzyrIzegz zxF58k2kS%?jF;y1{D)_`vwI`I#Z&cQt!R-G#oa>K72kmb4#CwE=5dFOdc<^3lM`<> z0KDEuD*k7>ZM=u5WR|yU=d+=5nfg}SWIhva0uy~YTN$g|s|)y6!uPOzHohJ^Hvrg) zEdev=;p$dDu}ugB@{R|+Cs=*6u;G<1#?(AqXs6beR!I0`QjfMaWB$VkFCp`fY2TMf ztA;M6`esiMy_$}oq92t7R=@s`VnyjP@Y{?n($R=K5e#-Y!n46OtIx2>t3qwK-^vbO zez;~ROnbhu$9iyX5uGU97iS6;M(e%|ju{=V5{=$U9JRKR5_$gS-9Buk#E0+;Axx= z;=TLQYT@o6u2&KzDv8`Amf=n9`~q?6=_qI`7SwyQOgI=-?If$0LtE36wP&3A?wH%B zt~glJ8PoXKa9eA(OrQ~?Gd!Zc>z4(oa=v73GpFsQ;)_GGc&mvr_gV209+$;8TFruS zt!trZrwRg&xbM_g$WInMpA)n;0Nt~3nGLVDV^+R!?6+21iX|!?oVn4tTW4g|21-#r z$CubYmunKypQL!KILfmy0v?9ZO(zASC8^Pu4G5aP)ta)DSktyAoYzf%EhMRzW+OKb z&pFwCH?~lBwYyt56rAbRp!ONz#Wy+PkcY^2 zA)e9vJht}^XN=y@=k}rcQ?p1HLych<)a*&@#I(+!@zp+R-4&jPfuFELoO~Pm9Ym}gf-ry`N0@!=Bs?%3vWQwE>bytMXH;2>Zl4KqEf{V~jR`s8i4i zo1nG4O`Gfk0tV+ur1%ztIJSKcfn*L+-nphs?m_2#;ltt9xO1vTeCT?x@J9h$e8< z-s`4Of8Qd!P9H*sf$V&$ zU&092n=?pyrbJryg0&wl`;tuMz?<5N%?0ca9J($>rwsS#M9*2{`@iX*^bE~Ce!3;@ zdkdtZ&_Zx8l#?7z!rv-icOvcIwEcMZ-YWgC17f{u15^7aB>=;>24?k^r#!}-D{Ppn zFW%0R=%`1>(lUuOu6Jr{r@|tsuOxQZjYy~NfaS%d-?hD{KtrJbXQlo!wlZd`hiy?& zlXUY!h^@t6ZfI_ATyV1BRH&zVQaoi-*|xYJwRf$ur^Kz0txN_PJ@92{TD^IEXSzEL zjoIu<>Ri_44ImTyK#9)FgN#pBO#R4nLAP|Ix!`;i!f3RO=Fg&qWw()9=sU%VQFOm) z!0S^dud5ZBu93)|U57N7uj#aC*Dp}!F1YL{U>`3YspXl~K(>S+>MKOH&s$i=U87)3 zq$pnbrrSOIXiUt}ylK9^F;;a{i9#{`jq)j+Q+=C40+7R+A>kD=YJ-?dE{bMnf60$f z6o;BRE<>uWV2MvogX=|%-lu97_r{fnW;d8r?}pYCbL$j8;@M;Ll`zE$b*SAaWuwg$ z_mQ)9x*8RRj>$E0Z)_I|SDZ}}aY`Hh7sc-=WlcA#SKy_|%*Pj+&WQID0rlr75eCbE zW@I9^2yi<%(b^l`pmfMJVnG4s>z7tx(I>Xh@l)%*bI*Bg8aKE-Q<)Hw=G@sv>=Cn%oa@v+=5`*0&6D*~L< zyv?s)(P^q`6y?5^Wqdq1pbB99?4`c8Z;~okj01oMLQj&`YKwQ@?Mi!;^t|`!24P3N z?qjp1pdaU6nOn+a7o1g~&Az!e+x|Kic$b$c{Yj+n(h6}p63ecM0a6&SW|g-EC3QG|NL>#A4B zMmm5m|F1M?{9Mb>e$LJuTTtDb9BJ=x37OI(xpG~T8glf=-ms*nTaJVc)GHe&>a zh!FJNGI(PZ&l{yIz4EMnuf9@cYxE=1J}fEs2$Yd$n!)WWdTe+yjoT10$-!b%Sdf$*zs&1o{3hoy3h}k*^Vv7mI26P zVbq+{^{EoO9VS*O{l8q31j2~rK&A0^65GOfD@Y<%T}oeMLmzK|EIl}cfBHKK#E~+N z?&8R4)ge*%J_(fEzH~AB%lHOzo;7i_5;Uy2o41`z2vl$w!t6AY=I}ZxoHl#HZ6gxl zNL=BB-2GqA4@Bf*R3oJOlWV#G3!mN{FZ#lW?~LK8oO~)aVdD-5p4od`G8yQ|aW>0I zTS|wOTFO-DtY~{Rd1PA)WjrW9qyG4Alv{S8t{ zAtc$Ey?zIh@+INuyCy~=_bFHCVSf301XO@MfB3gdTWl;d{D^xHXMSh{&Ijr4_6&!p z5-nmffqpvXB-yszOBDjq0WFgcbnIx_+q^l^l_UaPc^QDaiX z<~8}Smn!U(>!14NuN;ZMnH!le&u_IzOj&cA?H?*D>o|lmkSW^$`=exDA7eqY>1ZK5 zHUc)<(Vue7GGa-wHa&9n$a+!sIV)p`=;k5hC?KYyNekA=Sc>4}>Wg9w!xU1^YHqK&9Khfzv4%PFVq@Hwi)U?s*jbmG9z94lVP(P8gRCl!1kFi(pc>*dwP{uRh4_vstdoB`TUlfa_oh$D zwIeOO3F8Snr&5+_q#m2p-;l^9EfTzrLE)Z)uif{gZ4onsk*|a8nGX6hOVSy-;)c@a zyor9&Qle9b*|GrKt2DgKgpn(0+3ZI-j!S-{G9NiB#;XRPGWGR|6B{LFg9`EH zsy6-{>Knx{+t_vX^C_M5kMV{J3n1-Mo~YM1-gdG#%2kfA@UNZojI-9alUMwK;qSv* zv@H8EThr*bj`XG;%L1+egLVZ+Jrza(L4^)W2(QPLK~)FuDMDf`Z+ZGR^X2D64mk1z zZ5T&O96COgd#BQs7$01wnR!8rU6EYc94*HL9gTj%wXuwW%!hM@^lxM0pfY8sD2wUU zN5KZ%RCc|Q8Fj_*Q_Y5^z*2sf{1tnaDoP~DM_s^N3fFl*P7SqkYp^gLbA!;$&_g*= z)RAy?9HDGc9{e3dXzE*YT~wsws|`18-pN_=wy%Zs5?VQ4PpQvw!yedM|eqqknR=dPj8zz zcvQ|es6VAS%07`O2_<@xq9zf^#u%ZOuEx(Cn1Y(x0*kTP-7oR80X_f)>?GhbBfvx$ZrCn53?a=2a350W09A+cSQO&7LvmSWwfy$XLar-E*m|Z5YymVsOb5}h(|DZ zGO-0bpqm=QjNLm9QFK?djKo?mwdS=d9O0TWNmp%{+Q32kG(RJ259| z6Z_xek~kqQxqrX9me&s2wJ4ju_4`)m%5S(nqW`J}CHHA^MX`8CUs3@}g|#%QtX37C z5cm|&OSs<@)tcIg39ae1Q~=Lc_a~3JVa=fr;Fq>Ot}hqE%`c8Yuesht|2g$f?7cJD zpPVFM&7nT_ulH_s;SYwZVefq4VX3Fxs}m5lR`X^hqu;BodhgdB>N{nH)+$z#Tgy}H z^Puj_Laia)E5spQ_nI9vzVm9<^C2Tgp9a9{-iDMp>NVdAHw~MzKyI-A2BJMj?Pvu~BzRp-Tyv*ZHfXMu>G`aQ70`!+@Ym*>ZWb zU5Mn;FK~nJv-uw~MYM6)8*4RSvG~i_&<56H+gj{--NA2T0||C2m!+Piy77q(Et4&rDb_fcs_@y@ zc_<1|zUB9RJW>$7rlovH!wykAE5kV`5QPngmdF-P7ysO!0_=VE`FLG2pTnO!)&zxf z*l%%MSA}%n_gX%`A9nYCfBwRCGIf@{bdqxQ^5uo|@N|07RAF^X6n2vl45O6#D8RXZ zEkH4|zLk?&QZQZ!-h`^F6>PCrQcE1vbdQi1YNc4-keY@Vp3Bn<4)yzrPZYzxSPO)h z68DT3uDyYK0$R;qH59IP;Vz>xSi`{0FafOrhv#6c#Z>yCYjXTq!g{W%W1O5GVx^6) zoS<3%YB23q33JE;f9%W$mXe8mbd?-i6Wxd!bMMNpyYHpHV~S4_1W)hiT#%##Tj>75 z5oIv`MTEr9JSS-ZIfYHUT407B-Hbe4v!HE|UfT?WIn{IEt$%PBSC9jhcua9Kj z@A+~`5YT3etAa;qngURt)7xb2NE!>8KwM1eAyAd#(Yn&5yE~M;1}Rl>aNos zLNqJ`m@d~M&nF%Ri$Sf;_&e@1Ub58cqH;LO=D!`mlTv!|nJm!`ISBUwTAiiZYX-FX z-MT6c*fwnCZu?6;6~>uWvZj0L`G2ZUd#4o%QQW3Nnl5w|jK`SQFjqWwNL{Kp$d_Fc zc$w3%qdN<`Ft5tt@xsV8;Lm|z9smPS2mJt49&Tr`9vQ328>`JW4f*~|-JZi9s4l^c z4|>rzUs!4b1T61gMjqZfti9^xcXWE!ji(1bEq>cNt-5``r!OY2&N))IboZ6y!Z07t zbYwBoQtCe7cBk}_hB~V(-O;mRj2Fn|BRuq7Cm!{Z4Hn4xBd98S`!kLZ`)KI z|Ch|U%rpkkW03zx;Q1YPcS9kSvxiLP2|c$3F=m$Ft?g zZ(eVSa@u2>8O?+Cackeo*G*O0I>gSisFU{-)Kf_&Y+wnNvHUX09bO8`p{Gr%AjDB8 zrkjg$JVIRExKE%6C8B6~b8-dEFM#0?KN4khbrG**aU+OqJDYaI2PbiFlj{L+lX=g{ z$<027A)(%}?Wz@5ET_$=@4h@rd|s3|$4B>Z)xPMO#^H5tpLI2lxCvS>46{lVdMtNt z89Uv1sTvmax@pI{%*b$KPvPgP@pzc2ICQNW@cxC&7ED}#2Vu^v`nXc`xKzpI-wOC2 z#;P7_+_Tf_KG(i4k(lTTZX8I?Tt-^fm9j8_#e=`LL@>4~s3*>(U4e_VARB5AOe zM)3yB)w(AbcWQ&M+Q0^Jb>Ach)A~yAc6((!i^aP&A1gvQmw9JX9Gtr@->>-^w{Ti6 z)i}@JQ*s9D0?`rh_qaaC3sav%ZxRVmMmfL-di@`Xr_THtN#4Q-+;1HZE^i$RB{p3V zkcxj;y=&t*g>i>}@d3hPa!o*{rk0afr9|c!@>{bGm4x~&#o}vghh9j#m=znaqR5KxSdGyL&ts&Y5?)vKCDFES*&6N&vgv+XQuR-6!am&xv|I z_rd* zr(SYkL5dT#kYK+B5p|zv%21S;sGBYobJ?HG&gaUz+kjl{I)to9J=~Ha-Ily3KfNj*4Q}>e=5i-`gZ-9us&FYzD^;;?p)Q+H$Mm-qK zL}Jms=Ebac@0z5K>cLgNwcJR|w#5?}-+B87QbE&|qG^xtZ0-tk-!OU_Doa4Ctd9J& zW5%}7Sc1}>VwO16b!?yGaa{;Q%!#-c3UVv{&gdFlUHLcnx5oEN{#${B>Z?i7$T587 z1q~(hDxd^%vHUm8cH2V&!##pl(sJ_*@oenkwR-1OO#Z~_8~^D1=dKgZ%H&7<*Y=s0 zYL5aSfMFdCD5P>-!nv@ciIyQpqpE2}6RU8|uWj2)27e0eJ^`WfJ3ZczJXyU>Y~5%k zN8(j(!jruZekMo9l{Fy%Gs$1z-x4-Tg z4#E2QUf=+) z>\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Doppel/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe Doppel Integration for Microsoft Sentinel streamlines the ingestion of Doppel security events and alerts through a custom data connector, converting raw event logs into a compatible format for use in Sentinel workbooks. This enhances digital risk visibility by enabling users to monitor threats, analyze alerts by category, and gain actionable insights.\n\n\n\n**Data Connectors:** 1, **Workbooks:** 1\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", + "description": "\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Doppel/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe Doppel Integration for Microsoft Sentinel streamlines the ingestion of Doppel security events and alerts through a custom data connector, converting raw event logs into a compatible format for use in Workbooks. This enhances digital risk visibility by enabling users to monitor threats, analyze alerts by category, and gain actionable insights.\n\n\n\n**Data Connectors:** 1, **Workbooks:** 1\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", "subscription": { "resourceProviders": [ "Microsoft.OperationsManagement/solutions", diff --git a/Solutions/Doppel/Package/mainTemplate.json b/Solutions/Doppel/Package/mainTemplate.json index 05ae1ed9c5..3953f4f74d 100644 --- a/Solutions/Doppel/Package/mainTemplate.json +++ b/Solutions/Doppel/Package/mainTemplate.json @@ -195,7 +195,7 @@ "lastDataReceivedQuery": "DoppelTable_CL | summarize Time = max(TimeGenerated) | where isnotempty(Time)" } ], - "connectivityCriterias": [ + "connectivityCriteria": [ { "type": "IsConnectedQuery", "value": [ @@ -211,8 +211,8 @@ "resourceProvider": [ { "provider": "Microsoft.OperationalInsights/workspaces", - "permissionsDisplayText": "Read and Write permissions are required on the Log Analytics Workspace to create DCE, DCR and Log Analytics Tables", - "providerDisplayName": "Log Analytics Workspace", + "permissionsDisplayText": "read and write permissions are required.", + "providerDisplayName": "Workspace", "scope": "Workspace", "requiredPermissions": { "write": true, @@ -222,11 +222,11 @@ }, { "provider": "Microsoft.OperationalInsights/workspaces/sharedKeys", - "permissionsDisplayText": "read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).", + "permissionsDisplayText": "read permissions to shared keys for the workspace are required.", "providerDisplayName": "Keys", "scope": "Workspace", "requiredPermissions": { - "action": true + "action": false } } ], @@ -371,14 +371,6 @@ "lastDataReceivedQuery": "DoppelTable_CL | summarize Time = max(TimeGenerated) | where isnotempty(Time)" } ], - "connectivityCriterias": [ - { - "type": "IsConnectedQuery", - "value": [ - "DoppelTable_CL | summarize LastLogReceived = max(TimeGenerated) | project IsConnected = LastLogReceived > ago(30d)" - ] - } - ], "sampleQueries": [ { "description": "One event log", @@ -393,8 +385,8 @@ "resourceProvider": [ { "provider": "Microsoft.OperationalInsights/workspaces", - "permissionsDisplayText": "Read and Write permissions are required on the Log Analytics Workspace to create DCE, DCR and Log Analytics Tables", - "providerDisplayName": "Log Analytics Workspace", + "permissionsDisplayText": "read and write permissions are required.", + "providerDisplayName": "Workspace", "scope": "Workspace", "requiredPermissions": { "write": true, @@ -404,11 +396,11 @@ }, { "provider": "Microsoft.OperationalInsights/workspaces/sharedKeys", - "permissionsDisplayText": "read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).", + "permissionsDisplayText": "read permissions to shared keys for the workspace are required.", "providerDisplayName": "Keys", "scope": "Workspace", "requiredPermissions": { - "action": true + "action": false } } ], @@ -473,7 +465,7 @@ "contentSchemaVersion": "3.0.0", "displayName": "Doppel", "publisherDisplayName": "Doppel", - "descriptionHtml": "

Note: Please refer to the following before installing the solution:

\n

• Review the solution Release Notes

\n

• There may be known issues pertaining to this Solution, please refer to them before installing.

\n

The Doppel Integration for Microsoft Sentinel streamlines the ingestion of Doppel security events and alerts through a custom data connector, converting raw event logs into a compatible format for use in Sentinel workbooks. This enhances digital risk visibility by enabling users to monitor threats, analyze alerts by category, and gain actionable insights.

\n

Data Connectors: 1, Workbooks: 1

\n

Learn more about Microsoft Sentinel | Learn more about Solutions

\n", + "descriptionHtml": "

Note: Please refer to the following before installing the solution:

\n

• Review the solution Release Notes

\n

• There may be known issues pertaining to this Solution, please refer to them before installing.

\n

The Doppel Integration for Microsoft Sentinel streamlines the ingestion of Doppel security events and alerts through a custom data connector, converting raw event logs into a compatible format for use in Workbooks. This enhances digital risk visibility by enabling users to monitor threats, analyze alerts by category, and gain actionable insights.

\n

Data Connectors: 1, Workbooks: 1

\n

Learn more about Microsoft Sentinel | Learn more about Solutions

\n", "contentKind": "Solution", "contentProductId": "[variables('_solutioncontentProductId')]", "id": "[variables('_solutioncontentProductId')]",