From 9905c7dc8c1a22fd4d557a7a72b8fd351df38d08 Mon Sep 17 00:00:00 2001 From: v-rusraut Date: Tue, 5 Sep 2023 13:33:30 +0530 Subject: [PATCH] updated CreateUiDefinition and ReleaseNotes --- ...olution_WireXNetworkForensicsPlatform.json | 2 +- .../Package/3.0.0.zip | Bin 7923 -> 8314 bytes .../Package/createUiDefinition.json | 10 ++------ .../Package/mainTemplate.json | 22 +++++++++--------- .../ReleaseNotes.md | 5 ++++ 5 files changed, 19 insertions(+), 20 deletions(-) create mode 100644 Solutions/WireX Network Forensics Platform/ReleaseNotes.md diff --git a/Solutions/WireX Network Forensics Platform/Data/Solution_WireXNetworkForensicsPlatform.json b/Solutions/WireX Network Forensics Platform/Data/Solution_WireXNetworkForensicsPlatform.json index 4e0dd872caf..83c650a9fa3 100644 --- a/Solutions/WireX Network Forensics Platform/Data/Solution_WireXNetworkForensicsPlatform.json +++ b/Solutions/WireX Network Forensics Platform/Data/Solution_WireXNetworkForensicsPlatform.json @@ -2,7 +2,7 @@ "Name": "WireX Network Forensics Platform", "Author": "WireX Systems - info@wirexsystems.com", "Logo": "", - "Description": "The [WireX Systems](https://wirexsystems.com/) solution allows custom dashboards and workflows during forensic investigation integrated with Microsoft Sentinel.\n\r\n1. **WireX Network Forensics Platform via AMA** - This data connector helps in ingesting OSSEC logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. **WireX Network Forensics Platform via Legacy Agent** - This data connector helps in ingesting WireX Network Forensics Platform logs into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of WireX Network Forensics Platform via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).", + "Description": "The [WireX Systems](https://wirexsystems.com/) solution allows custom dashboards and workflows during forensic investigation integrated with Microsoft Sentinel.\n\r\n1. **WireX Network Forensics Platform via AMA** - This data connector helps in ingesting WireX Network Forensics Platform logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. **WireX Network Forensics Platform via Legacy Agent** - This data connector helps in ingesting WireX Network Forensics Platform logs into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of WireX Network Forensics Platform via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).", "Data Connectors": [ "Solutions/WireX Network Forensics Platform/Data Connectors/WireXsystemsNFP(1b).json", "Solutions/WireX Network Forensics Platform/Data Connectors/template_WireXsystemsNFP(1b).json" diff --git a/Solutions/WireX Network Forensics Platform/Package/3.0.0.zip b/Solutions/WireX Network Forensics Platform/Package/3.0.0.zip index 802f74749e714bd46b74e5aedb9c2d07cb22d966..8d2f2c515f8193241c4c803d91245ca4b74f7f5f 100644 GIT binary patch literal 8314 zcmZ{qRZtwjv+j3s*UjSY?ydnAg1fuByIZi}?gV$&Kw$9%cL@?4frL!V8za(ngCgGrUX=xyZ+B8{TEmbljM?}+`A!!_Rfd;q^0ZJ<+hb=jS! z74S7ej4(YIXQI0TQb6h2D)74}hw~I;BxOVaCKA%*W@=KQ@7hV_np#s0DO{IH==4 zt{KOAKjgS2m$tvYJu({aM@2QH?N>xa-RQYl@!LYTb80Db-B#%t7Pa<}>mH?Tl_>c# zWRH~AdsLe}KIYHK%`;XQ2fsyZ_y{8|d)!89ujX^Oi`W*|QwH%X)Cf46^;D*359<#- zEBg(fX&vQ?fay?G8cGZ7?l$zTbyEioLy9`Zx=u|AA_2o zA}H{nste7*nRR>62$zM~kM}7cMh?p3+vVk{azt_wmEd;~_fd3Jhjmq^{1Vu4*RNRG zDz@2og>m;)`NQKzONT+XMTZFIT z6w{(k$@GjRN(u@Siz~BSF7zpNgw0+BAd5}{xv^rhE#XA}2sg`xhc~mcfB8D(3;bEI zfGqu82C$RQ$P;?gI+5MoqIAqc$_XFKpI%;MiSg!3JKHI-8?s`#GZr(&KQCa(is(=$ zw|2cVT5&Y?w|qR#qidk{jGt8iTGCdlyI?v^1NU-r8*Q^S)TR%`QJ?alEc@i7gD z;PK_u{Dq#merd0YR%;E*AwmM7QyyetB{wAAlDIW8<33&gjZ;ccdgBbgs9%~HLd(`j z=cG-S-_)_YH`IL$+7%8zHqhm?RHa9crwIJhFZeTme%Au4wjW6%_={RnG-bvvUXaj> z>Uac5H6q48thXhHM|McJ6fOD~nbe(|&X$ypdHPS;N*PO~;Phu_lzBmQNiD+6R$Om) zp6W{1cYIGx=lUkzvfz0g`L$EB;BRN+O<&6UYx!IiJI@o>H`ssBfI|AQgXhb$lN$Zd>nonh943f~_~ZGt=VpGy_A-1N$4Hzxc}b5^aepb(lP_ zv)B(=iXlR8w#J7hX%|xpv-;puqi?_EhdAzqCdH&qE7$3>XEW3XW=&Zf zxqqZOBbl(<$JR%fZT)^FuiVnYZ_4OiX(4s#kv&}2OCKHy7NawU;zFmlmyVkoDj#)% zZ9v|+2J-Q5a+xKc4A-OoI;?p00uj#)`=j)25?wRNS5a%zKVx}uIa_3s6e*?U7o3nL15#qa`k_Q!Bc2jp(&M2WVeRn6f zTelOJvXjN(m^CQZnl4=^7*=~jFX~)^I`A!;TOupL{=tC7Wg%hD^&c77iT+Y#P4zUl z5q8Cfe7|9d{Qp{9yBM|^Doq6Op2cm1&geB~8Ka!^_-f!(dAr+lA9)cy1x+XX0q6d( z*$~zt%S?L1DcQ2RiDs;>5+I~e%5Ry)g4(7}Qfk&Y3fVK?LFw)XlHSVXdZjyEZ_>Cm zu?;SfoE7h;>S8u%8ONM^c5lm>`jaw<8lQ?X_XsrKKe;%AgS^KHY&0BSgC&I>zpUob++NYP9$psgoMPEq0@h`?#rZ{nQ$_NFa6s@A5| z_r}LC`_%Vh;Pecr$&W|*0b@05(<{SUu!e}n=;H9tP5+OBo{8A2|GW9kj^nqe z`q3qlN(nCZA2GZ3E#ndVMPVdMNfsRrUy!PzW+7CHHvnav%}wZ^8~Fw&5i5M633>*+ zPp|xePuuwRYc1QT%u<6|J*Cd6;|EZr|y*WO4VvS>vf2)o&- zFX59d3~q`P0P@3B>cPj^#*IjNc~296mi#U+D^DEtLG*0<6PbVsmryg1KST&IhfL6G zV41?Gf80W}gx@+(%E*PLzrW45p98%<1v%jNsL^*1hl-%9*t3e-&F|4aObG>Up6L~= ziE?2D#(jfoQ3{51ns9x&fa({DSxMaG=ip8STpX2SwM=S?>=jpqQyV*)QJz9-r4i?! zW;iDvIOS0LkJ=|+7oPeP4Cp>P^`av^ro)T@XWL^-QY<7!ouj*atb`U)Ox~oO=nA+f zj1&wAefik;`B5rrAODJ~lKA1AC%!}_y6sj=whuZJBg_EnTP4B9~O%w-E z7{`<_$ka^s>rMEh(YO4W=#=FG+z3~Gr4fe4G&~iu4!&|(!5U_opWJ+2dn=iulhaeFa{xZ|4{MeK%x+MwNBa}uo;O3iFpJx)QD9UyX5`cS6B8M5=s@rO#@}?RK zI%U!$e&H^`HfLB93nSG|r6y%W`0}hzJsormd$|c7jdzpF=e|nmBrFDez)00kv;7-a zb&GE&p-7@siXoD(ipUT^$5xJ3vv!PW4_@B1J9g|$SlpC@y|_K zU4V3I`E%GYl!|8*Ng!%48$-}?c=4;#=35UUiVNpk!;0x3@&I5(0MHE0+-JjVJjixDV!ebg=rAR&sFoIgvA|bA(y>*rv+igw!yCsd8Y8SkiZ`&mpyw5~IVwZ)&|m@&VAl zQ6P47rs8v7^TOD5A6|iS?RGA@XYIy@$XV;7vWsEd9LR1diS1z$E@s2o;VQcG3PzqH zJp;nEoLm3h>m?W#Esqk}#7ki}OBE*4Qn(Px1oktb& z3XbUK%_9q^4_1Nlf+~W zXKDb+CqLk49f+|wH08@T>lEw+PV$you>Zrw9zY9=#u}-cdkZj@Q$->x8{ml2|bAK1g?sN?(hcs zf%869_LI2V`D5(Rkq3$u8vOv5v)rgWXPcPAR^mjO1gvGtdW7=caA9~qsq#VX;{l07 zY$JO&k`Cx32iM{juu*F+SqS@FobxNlT$<~H{ej!_vFKbJPBbo)0qTSdR!*4X~2|`iRf0L(%#>$0GZZr}->?A^QCYuhQd?_SadD zdbbZXx$XN-JQluE6c4TUM6DO`ku;9Tj5&kX0%KnqpxSJN3Gm_-pGsQPE(Lra+dJO!TXu-wItgu5?@p^kz;W{9i^XpNGB$Q{hH{}4T8#r3}i z*6VjR#i%A#;SV5Q+sWh_a>4{GiOrMc96cf$s&K-8o@E@TfH*Cet2!qh5;lO#t^AQD~muXv1X@C5Hkj5 zU~3u7;M)7P7QAR1e+c^3I?2!55XV1l$Rc22CI`6^$jY6B*$J6E)jDC%Wu$O8 zSn(@W<``jc_H2BM@<$T$w-0&nLhw1wOhqFycUUz$<<7{E%-NJol;NUHZYidv+`~2u zLY+ZeAL)2woHl6|F-LUaQFkh`dbCRVha9Ragud^cZb@BkO@(x~H-vuWAL8Bh;cRlI z7s#edWml0;mzOn{f~_|tHY>ym9!&eFGvLm-8_4WRNkL11KJwmQInS;1Fe84>XG4Iu zupyn-wQc1K)q__9rJ%3JE3>3;mrQEcp0Oig)H0~=c+qeCM@xpY+Z+4uziR8A`{vTnyaSNYs9fmi&ol zhC+yLw;{@^onw_AY~2M$rZt_?5T`!AjM;6d?l4)0g+XTmZOq zt%G;>XR1f{Kju^^Cwut8XKSn}W*Abq)X8VKK~jVqkWt#cH+ERuHQ$d+G*J9D zveXh>v+t}vE#={Gk<4w92yCRIl&IYe zu_o}F+D8UuaEG%*zWq)-7sw4!X6PelgnIl*%(Y#)RRT^QM>PF9_xX8T`zXjpDD+I} zqt?R}`4?aW@=s(P{VOa*yETQjok|&+%1aMzqTc-MJm5rcI`1#vQVWT7>$8Km_kFeyCrg>Pdi7^c-ZW(T2n{@Qds5SSTsb@O zG@xyW>9rGe`UfkXuNEItM7pM^n5*GwIp-6rS+T>3P*u4DaTBAo4E-bnCmxO@9C9+# zwaf43sU(g)1S|+E8F(2$5gg7Y7 z!&K@z5$TUwPyc2xQCHo|oI7sW7mg(|)o@N;Tc1Hn7gISyUcmAgsg0a35vUj@}1UH$3WxKjDF_CbvBiDyn9nrL#N zexQ_tLUhf72ZnPCAsk(9}S#)6)`?legvs>yhr!Y+r?>)3o{f z_!i^o#puMvN{k6xgMDOfNfmxx3Rm{h8rx{q6BT&;J0B%0dpgC5dq;HOSGRH z)2#eyjI(A67f#ZBnS8(+8*&Up5gR0<1zHw*CP#NPOyfuglrjfD40J$?Y2{hNX;dHC z(~E1%(@H&&N4q@sDAE(S)8aI!z^G}_9`xvswKNovjuNSbb`F;AFC~_9eZ4O?7lPbE zo%69d+|KUgbpmzYS@WN{b{<+vUB7m0W=F18949dAo_KWdC`~5+qKP%o(p@iZF!h^} z=Uku{IpjIAPdfIghTilWT&Wlzt4Nsz+Dg`>AUKu=hAP}1dx84D56(qI$bt2&JiSK` zoR}4DSY>S(A(aT~OoQu-2)t>8+-LhGj2wr0dW|SM_Vg4sD1&&l;VBxntmrlwzZ0uK zg-vjM9v&?oWA9Y*x6AoSJUe$zYER2mFEta428N8m@XJY%m@>ia?$a!=5zLOnq zmXo=dbD8|5UZT^G+LE3Ay8*hLlUN<1#3T8N1LLQEn%bNSBs3jH9rJ>6DOvQ-cS)_- z?3NvsO?dmZJbi&((QR^?)y5ej*BOGRY}lQ3^VWC97evyIxgsTkwJkQJD&Y9l zwx|GL4efR4OPLVvE8kHI!P7nh<;C`X?=#~Oa4o4f>&|QTj}j~EAH2H-S~d=+G^KD< zX9Y1ISC|)Ha#&fhzJ#Wsr@EkEu3YL&?G&OTRwq0I<5NAK3=vE1-P+66z`!Q^$4AQL z7kXB&z{-?+bxX9digB+$;gI{k1HTZv|Dcw#Y<#RQ4&aWWe()%YzfEtc>mFR)?Oxn- zv>aqh>MaxOkS|l66e?ZVd#Y{7bL^(^%*QO3l5^19#MW#H=2~N@Z|EqwsPI= zZ4=)udKME36VP{t2RTnAr78O(o^eS`0X*NVRu;PFup6T_ohAP!oe zIWDqF{&6zIm0KbbVWAAW{$SC#TWJw2j)9`W+v42e*(e~N<_BE(_*I|TP-fp2srs{{ z^{lBhQ=UuqODtPbBVg0{lqhaMP2_PO)McsbKYT;`cHD@M(|hBXi6h-kC4AIIWj(+g z7evMQlzu7Lh=hW_L*vj#7h;&fIGC!IwFxH|#mJ;A`k?Sp~g4*A4y zHL^;H$jQZ5*x~RQy`6fyd0TL^T=cgE-B!%dt!kLN%t{eN)Y17EeuFzdCBOfW$WspK zn!|Q-NLuFan%?qXT&eow2k$t}710$?wU))Y#W#0#QnX@+BQLaXRt)+H@hd;+o1{>! zr#@MEi(7zWCP=WQGjRAnMfn}mRuWa$)=mO5I{D*YW)}KtBlqX?r{6nWj&-Tn1#wOC z5q?Ftl_S&?hQS6>D(@;RvOvEQL}1bsUE=QHZa4}SMUt-)8LiBRnf*Poh_jqNof|pn&mg5R*f|19+T?wD)tNsmJiW$T<@4L6_k z&)sAM5~kcb;1fun>v|*6ROVh`#MF(*UWI0x1duS^@tO9+jD= zCF6K#dqkLci`Fu$%2e$WvrewJDvb1-@!n!&3?x#Yh9J>vtXHL;GAT& za@TUli|B&FA;$i8bk}r%|E1*cRYf&N<(ep+ci4@96HQQ`|Glpr{M6dT*^|*Oq~8&E zMoANZ=_h;QACH}N+w&v74HI?gC$k3Le6vTP{HVD3tGxSfdG#K79s>h{gL+<_BF$a=+Z6eiC>~;Pt;M5KxeDSbA4%^x#5r5qB!&P?`u5@=7t4L ztkYYcXB_@mD5FDm=Ev?vdEVjn@e&(Pi>ubnLOEk|=8(*Fhe#H>y;*WA6?8Gyz2kE? zF5IH)EwMZ~mJUu7TMi~iiRG!~_=jVYPjGl9VjNKEH1Toi+_L2s9mcxyN-$)z%QQyI z(_$rz(`{4}_Hx{OuS(w}IW5f|h8-^8UG(q`&NwQzhE-mqjb@HE2wIv{$-*UH2WV5H z6O5r3=}1~X1WJ3r#)#XFfG38szt0<_&+(VW#%O0E3r6^yAcMiTq*SS0aCRsxcF79+ zffq$AihF`hYBl32a_5)pMT_E0R>nQ3%KYB{q5VE{6o<12$1nQyv3=VTJlveoNKp$ zAe3O;LKRaTr)4ZJyQbH%cgT%@ldC9V<*y{)pt4~Mf%pTdA!X~$eW}mjvM^Zzq0hTk z4`rEkE@Daas5ZJ%@wz>$IXiF^!Q9|UeaKXxJ7 zj^Kk2=67?m(VbubDj}QK!?F~?v4uPhd<<~Eg(9wwD$=r#@+n)BZ7m~1U=?4X6@$v= ztRDS>qt-t=PMVc2&I>kvTm5(fT|(x+$41hC?PmIB({%164iMQLZtpgUGs?ZCcnunc zw>8W?Lv5_fwF84565gg2J?J&*UqeX)azv&zS!9egRxAamCf%-jbL>uj7=h^M*4YI1 zf@u+Y+LPN}7gpc8=*dc-wKsgsk9;-)&x)*iQK(3IIw{`D2o+6g=p++N0+0n%rPZOM zK`23hL6^!Il$6?q^G2=KoX z{(o=+00fZ#C;VIg3-AB`oBU6B<3C6LZ<9~|J`emi*r6g1kMN%on1B28zqm#ApX|Q? D-305G literal 7923 zcmZ{JRZtvIkS$JtObG7oE&&F2Nr2!Eg9Ud6*TI7guEE_U!QCYgbkLxK6WlGpX5agG zZ?|@D-&vWx?ri6@wkAQ&i20=iSL3fI^>E{v}0>bOR6w$xz7qF$7yQQ|R ztfiH$ldZe0vlFMCo3qo2p1t$xFv0VwiEAI)bZz~3Y6=QRtl-dsXEK5Yxvb)ayIc`}_B%7B(`}hxq-KV9XRG^dca)C<9|{k!(szEmpK*%@pRwKf z3)rh{NvF^zhqDK;2UgX@;%PRXtsc{hL#IkpQ@s>xt+{IOjbAPY*xEEoF2_LOlv>#Md_TNqh0D#BIW#9$6!p|UVw1e_@5PwJ z)vVQ8kl2=OYxx5-)6A|3^90X!>0y@P0^bkmvx3aEcMXd+%4zAWlZj%)IdrPGl^;5d z7gP)~uChs06e9~BynLf%v=zl<(l$4bS1pDo7RJWzG`-@B`nzC)F>9daNShjsyn)fP zp4#A{vBJP14#j<| z+M59qkeeFkM_~V#%HkWO64now5&pI0pym*~%0_&Zq*ONBti>NeeW}5Y+QM9o!$bEJ zBIxl4j~sw{DEo;hNi31e63c0TQydN-ZwSSE>QTLt>dzS z0I1N48^V;MoB2i&Uok-+0bN&(_>a0Ah`{{bhG^GTd1M5dE}=N}=Wwbo%dq6P_P}$9W6oPhd8osWZWJ2shlZ~PW!I3IV=g*iT}9X z@Yqtn$C~)D5;O|r)fwYQZJiF6>XEz?{lY!dhTmKq@_{3*^cGn&e!bLQeuVM)o5zsc zhOJTX^r)DCm7@bpwzjnJ{TCG&W0cMo<|CE%VJsa>ogfQWM=?273yZiPIC{#GG3jY| zf9mH=(U?TX+x80!L$xr)M(Ew%AAaC^Uv^{7wB$@RnTI7=c}SC|QO5n|OpUFtcMroRRVKT?^?ErmzvWQi1U9MsOc9QaUkEtO z;nrUIP|gWu($!7l1!!qFg|a9?6Wu@Y3%*DM8vi%W4bm2k!Ve z%jwEyGYlh^BW_j|aW3gfVxOZpd6yq7$CAub*WBw*GOFQQzvv=%PV$mQ_dO0nkgr_Ah0kvM6_ejB? zFQMZQ0wFF|%tBM`uth?AFUs#ZnQ2qbmud!u)M*Smmzhi3f65%xyJ`HPCu)X?&|G-d zD2^^OLK!h5>orzUl15P@c;K!(a8_MW1)3VT^m{fAZ;MD@UqI%VijXkOAsd@TG?N4= zHqxQT^iJ+SXOk69Z0LfsJa6uy`^_1;m^IrqGluE0GrG|^@%>@OEEBOYWxvpvNAu4Q zz=Qp;Z&wd)WWwP~KR-cpQx4Vm_du1xl^!{$m(~gfX_-?Bh81McFYla1g-AAJ4IiFG zB4Z_jqE@-#G2MOvP2o~5@_FcP-0%2eBPiamvF4Bi)L!T0ABxK78X2m%xWTHWOpuJ+ zY|6fs=V%pi-2Y)X$HlYiVvH^Whm;7>#`kH_SR}to`2l`NRfF0M-{T*nEjCcu%5Lpvq~%U z(^GVvVKiZHuZH>}Speb+O|hvli`^f|NbeERF?6z5F3XU3a>!H|*OKfj%1gVd zmH>bV=8uYxEj|)5Rr?xY-yQKlMpIv}fgl8cY(!zf{4HCT^%Qifv{EpVW$X?H_hO(u z-P<;7iP)iKH3SdEysGfqlVwQLF9&$Sg28YiQ2g>-q)!ga$i7=VoDewf^g25WB)6n`I8wb4(20Oxz1} zSEx@OS>)6y>|`<1#F_ofVY!~AgE+#F_cvy>A2EPIKr2G--I5&(iS-qHd7uG;r1oFH zP|suQkm4T-wu~Vl;QRwaM>AU|ElWoihkuaxe_;^hr@1j|(tm~Gy zqi5TDCawAj(xl_G&p0$U-0e2SQ3gn=xEoX5``0p4PGV^FP@ERl#iGOg!>fg}>%TXV z34IW5Yx(`#O%jq{Ti$)S(2=d5Hcsfbs5vld%4G;64uufhC~#yrd7|d5X2Q|l&Hi{c zoQm`N8b%J6zes5jded*c!Ao@Mo zn^1n~9LQDpsuY*bUg{>#zJ&@q@2P{s(HV2$(f8c`xk8-5W+U6vs^%HcL9mnssl4pl zyKlpbX6~PiBX9s2``lm@j?JeB1hmIdqNaK}GD0+^$+X?CaTGBWkxb|8#+=NPBU__b zoI8pxn#L|4Lu0(rOq@zoLBdUV5-;<&cr9jW!JA^3-fV7-djFF$k|O9&k{~@+7LU1t8(SP#Fg`nD57ih;^|pS-eJv`e2BLAq zBm&NP-~KF4y92~bL3{ko8K<~K!q7wabE)66yoB&Uq%GHHGS)k`mG83Fbj%ii(&uUb zl;lY~Y6;nSeO1rZ@#qwA=g_RD%UMU{>bI~TXt@q?Q}~E-hFeN3Pk~XNB}XhLFL~Mr ztqAY`k|%s$2bUjawwJkib_sZHG=n{KeY>;RsTJ^h{yZUvq(`&=I&dCxjMm%}n|M@b z%~!aSx-UzERmLNP2ERc1vmMM!$`mt8sR3{OK{q9SXR9KB|M1QzTbQfBP&L;H^5lMb zvh#Cq?~d+eLZ6!c+@bQ{qhUCAn9NApZ`jH|o3&kxSOyMwFt8y{E9S;?*f$O8|7Mq< zhGdYjdUED*~>nCIV6o zKY&q0v4i*rY*d-ohV|`)cdhyOK1|fg=Tn&%YZ7;+YItnc$}LNLWx0Z`v)c@YkKAJC zj|{O}ZEG1UxrFYZay%o^JBIGa3ze$i`dsi*6xOqnGqy0n*4ysw4q>txq|wX+-ktgH zF6VTNDM)UcdB_(X99w7RR=^bYt%)e>R2T%T7By?Pi-4>I(XQ0rE@GL*eG<{qKvxZ? zq$=o%l7XJQaT+k!VXOTsnam=|CFK40zhA!l3q^bvIcv`|i6JhTZyxe5ZP51PN@7YL zjMAC(?5nH9ydGqqPL>aL$}KN7X;3C3%9n4A=M}3+KJ@LMQ!8eNC39()GEMM`9Wuj` z{itEdX}lm>Rp9`iDK>}92R3K@aPIjvo!_`?EnqjWbH!EKzvU&%%YT5NtfK}co=Dw$ zH~4I7I7v&9R&THBHx}1E=4Sz>c)4jC4qD&cnWJh;Y7j>evyOueW5&?A!?_BZgw9@m z-kwY}D!}NL@gqh*6(mrsY-!4qlLnKEtz8t)0zPcp&LK#qr*pj9>F$^^y}5`hinvuy zN4;n)Iv(k_m zik=?Kyh|gH@tM4k}FiM~ro*WEB;VVa?@?_$RxHu~@8zi55H7?Z@ zCB=DZM3;6KbN#b%BELX4N^z>uRX@|$_&5f6qfF9#>8*z<*$2&?v4)>CUG+H(%UwZN zbJ*Pv)u??-LNz%TjnI5i_(d zg7!JRx5AFFKF1-FUPz7dDxVMVMVadX3#7t?7`#an`NR;mLBTECpz~zw*C>h*Zbq|B zt^#x$jNF6%K|G>IY*(bCgiF=_!xZ^BhJB?rmS2hRzZn=0$-r$_6@6{>a#r_TSX|ah^?lP2`H#csHohqOlqkh-MMY zGV4_=!AE^;ek*~&-74QxE>+J495BE$c6Js1zif{wx|40`n(~-jtEQ_T&WwE>^vPOd zX2Ba@_i{Hnkam6NieilB9OGB%Qt|vl(8vwflHkuogvV5c-!!*!t+(DV{%rDW7(jKd z`-j+u_?>@#MxUlUjC94d|ME;)2_Wi8KLEA1uzQNN`(``8ije)#HUd)Zl9?i_@IL-1 zPs^WeYA%c;T)titN=2tcnBINH6Zs{bX|sLn0H@nm4&VcomIec&0M&#u61b)ux@XjB zI&5E6Oe{+3sO=wlnT#5pYtr22wwPx*1%#7aQ`D|{@B8uZHcAVWW-ih=pa2j5iM*`g zZc8WP29oT&rw^d@FrLd}gqcv{WTXE4zZ_f$g{i}dkL$os_h`s{w6!Q-LTxSzk*vAGs`f;U59d}Xm_ zxXJNY4z2)1zBu8Lg37~SoNwb4m%_1q#nK|gaUUE>E4Fdz;^3w`zeBP2QzXx0!JDX^ zHN7^y`$xl}=&T``HDx9gfCpk*V{7|H)ThlxM6;BFE{>nTmK+j?`UvzYg;~Cg{CLKZ zevD8AO2Zv_$uM#DV2um@l3>ABzR=_?lk*_=hi{o9vltX2k|AHg3EaIF@a*Z$v6y~@ z`7yL*Ime(F!cPPv*m&tsWv7o&OefVl4E5ER4%Ays<>;z6VCBv+mYuJY2Um(VBFdNN zjYf*eTNv6UEMg+los=R z#yw53<=>1r0eM?UR*H|5Xq}{iry6XO3#WSB#7g+3pZQuh5x-Mc6aN{%RviTHVKrUDB2x0# zcNwh!t&H#RZ03pER2^Ab1b4oqC@Ot(Fgr|Lz^$`9rF{tyC=*_BqK6%66( zF+|d>Fl|9C2RUf-5S|9!8Y%2IRcf4p=V<8A6$U*)k;(v{m#xE~Qh%0-pyg!^ynWSk zmC0iU-FN;nK4LL$p*DV;zAS&=Ut;80mtWC{V=4-2iMEq?a7F zYWe}dwVktUwv+>i6EJNysG5Nu$bsK$JZiy84F*Sz9^7RhW!t{kg=RBj4P@wEiHNN zcmtehx+SwTnj)yL%)QFWP&xTl`Pbrsf-6?1bBl~d zap`xCmBrKUP_e{!9)|=sI99OSw#un7)#yB>>+;@8Cj<>ep>`5B%YNQcF(-_*lCd<* z-{ir0_tCCU4u39zfgpy~03*q^y@jQ)$Pj)vgyk+d$Wfv*iFCbzi3R0HkvI+fCx9tZYxK7%7R%X&qS2vz* zl-z#dY8g_QR%4adpfjf#EW%$`HeWn2&Q|&!HUQla0wahBzB~H08(v@!PRmBnVjVqj z{LAWW#r*b#A9;5~=gIk9%arSl;M1eSeTBLo-_|}E{}pooI1s)AaQ^HR9Rtzx_MV8T zU~FH96OqitA)CdGTqF!zBpq4D>@h~3ed6=JsY5Aq8r<{f+qK0pgL<}t z!+^b6Ua^_JMn2kKR)uprw==I>FVG{%oCQ=3_DjR{?Y<;^yVyj-bF;obt3$i1;Zkt2 zRTb8Y67W8aQ#^-RrwBL;E479_y<3yWTK4oPkVitz!EA^!ce2rinr6ME_&oq z-8|&A*2z0+BEb8=KlVQ_1qnNGdQHZ>2F*{rQ|9kt8knd8&`~d;DU_H6p3B^xLFL% zFvj~7hIeAfwfR%*aS5N`I7wviRv*grt4LG5+S4TxUi|6DrhxDVjY{i|?D=MP`?5Do zxbe3!KabotJXzq!!hOJ6&z)bbWIPVVgY`*o&}Sr5r8_gQ?};PFaafVC`irRRdBR4N zGceaT{IXmlvxpQeqi9H7yj`UFS(p~kmNm;4gN(0m7Vgt55F(!Zv+mtXG23WB6}ecU znz|JTZ0xhXkaA_5u;0EKk-W@puzdsq;u_fR9 zt6sQ6lpKfgTXbJx8!Ar(3s3&vTVU(Dn->9XH@DrhcTyXre(~5R4fz*OPu@MNSSJ7J z4xX>?E^hzN6>n`%cnY9${?w6iB+TbOzv$Xnvu#6Hf?aA{)PwWrX^F*%!F6tVG{Tl!Ja zU0?_rU@Euv_V#!SxWQUGBK$RvCa+x@u-={4`GrDymvk?yShnZjF(l3dm2JIJ^r5(g zwTdiA7cpf`VBt?C+K65#q8)YwdoaETbp$V;tdNv_(9#acQr&%kEK)3VfA1pjF@U2;=I9ZeeOj$SqBt%pI5zo(xCes1;t{)IR9v3x==G>5o?7X; z7az=cP=BA#Tl9RT@1@cfMN!RTI}hm>Cr-d-ksjoil9dO~7sS8bbmgq#G|CNGlvyO= z6`QaKW~xK_#LV&>z-6bUEukdN4XO?s6(Ay6rEjhjT@ zk3l6MyOgYLT>fr4m`&;Jb}6HRZS#qhLH*oc&=IgdW+S0NKYoBDo{Au1OZd6gIx-K* z9McI|I!F-=qY_uZPx;;J1eT(7c9c}(US1y+=nojtMjVD z&~Co>mq=wOV0X0Rics Mh5hsTl>Zt12O*DiH~;_u diff --git a/Solutions/WireX Network Forensics Platform/Package/createUiDefinition.json b/Solutions/WireX Network Forensics Platform/Package/createUiDefinition.json index 60da8b81f05..9bd6898d184 100644 --- a/Solutions/WireX Network Forensics Platform/Package/createUiDefinition.json +++ b/Solutions/WireX Network Forensics Platform/Package/createUiDefinition.json @@ -6,7 +6,7 @@ "config": { "isWizard": false, "basics": { - "description": "\n\n**Note:** _There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing._\n\nThe [WireX Systems](https://wirexsystems.com/) solution allows custom dashboards and workflows during forensic investigation integrated with Microsoft Sentinel.\n\r\n1. **WireX Network Forensics Platform via AMA** - This data connector helps in ingesting OSSEC logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. **WireX Network Forensics Platform via Legacy Agent** - This data connector helps in ingesting WireX Network Forensics Platform logs into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of WireX Network Forensics Platform via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).\n\n**Data Connectors:** 2\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", + "description": "\n\n**Note:** Please refer to the following before installing the solution: \r \n • Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/WireX Network%20Forensics%20Platform/ReleaseNotes.md)\r \n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe [WireX Systems](https://wirexsystems.com/) solution allows custom dashboards and workflows during forensic investigation integrated with Microsoft Sentinel.\n\r\n1. **WireX Network Forensics Platform via AMA** - This data connector helps in ingesting WireX Network Forensics Platform logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. **WireX Network Forensics Platform via Legacy Agent** - This data connector helps in ingesting WireX Network Forensics Platform logs into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of WireX Network Forensics Platform via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).\n\n**Data Connectors:** 2\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", "subscription": { "resourceProviders": [ "Microsoft.OperationsManagement/solutions", @@ -63,6 +63,7 @@ "text": "This Solution installs the data connector for WireX Network Forensics Platform. You can get WireX Network Forensics Platform CommonSecurityLog data in your Microsoft Sentinel workspace. After installing the solution, configure and enable this data connector by following guidance in Manage solution view." } }, + { "name": "dataconnectors-link2", "type": "Microsoft.Common.TextBlock", @@ -72,13 +73,6 @@ "uri": "https://docs.microsoft.com/azure/sentinel/connect-data-sources" } } - }, - { - "name": "dataconnectors2-text", - "type": "Microsoft.Common.TextBlock", - "options": { - "text": "This Solution installs the data connector for WireX Network Forensics Platform. You can get WireX Network Forensics Platform CommonSecurityLog data in your Microsoft Sentinel workspace. After installing the solution, configure and enable this data connector by following guidance in Manage solution view." - } } ] } diff --git a/Solutions/WireX Network Forensics Platform/Package/mainTemplate.json b/Solutions/WireX Network Forensics Platform/Package/mainTemplate.json index 536b8b08562..a168d9c9468 100644 --- a/Solutions/WireX Network Forensics Platform/Package/mainTemplate.json +++ b/Solutions/WireX Network Forensics Platform/Package/mainTemplate.json @@ -30,12 +30,12 @@ } }, "variables": { - "solutionId": "wirexsystems1584682625009.wirex_network_forensics_platform_mss", - "_solutionId": "[variables('solutionId')]", "email": "info@wirexsystems.com", "_email": "[variables('email')]", "_solutionName": "WireX Network Forensics Platform", "_solutionVersion": "3.0.0", + "solutionId": "wirexsystems1584682625009.wirex_network_forensics_platform_mss", + "_solutionId": "[variables('solutionId')]", "uiConfigId1": "WireX_Systems_NFP", "_uiConfigId1": "[variables('uiConfigId1')]", "dataConnectorContentId1": "WireX_Systems_NFP", @@ -541,13 +541,13 @@ "instructionSteps": [ { "title": "Step A. Configure the Common Event Format (CEF) via AMA data connector", - "description": "_Note:- CEF logs are collected only from Linux Agents_\n\n1. Navigate to Microsoft Sentinel workspace ---> configuration ---> Data connector blade .\n\n2. Search for 'Common Event Format (CEF) via AMA' data connector and open it.\n\n3. Check If there is no existing DCR configured to collect required facility of logs, Create a new DCR (Data Collection Rule)\n\n\t_Note:- It is recommended to install minimum 1.27 version of AMA agent [Learn more](https://learn.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal ) and ensure there is no duplicate DCR as it can cause log duplicacy_\n\n4. Run the command provided in the CEF via AMA data connector page to configure the CEF collector on the machine", - "instructions": [] + "description": "_Note:- CEF logs are collected only from Linux Agents_\n\n1. Navigate to Microsoft Sentinel workspace ---> configuration ---> Data connector blade .\n\n2. Search for 'Common Event Format (CEF) via AMA' data connector and open it.\n\n3. Check If there is no existing DCR configured to collect required facility of logs, Create a new DCR (Data Collection Rule)\n\n\t_Note:- It is recommended to install minimum 1.27 version of AMA agent [Learn more](https://learn.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal ) and ensure there is no duplicate DCR as it can cause log duplicacy_\n\n4. Run the command provided in the CEF via AMA data connector page to configure the CEF collector on the machine" + }, { "title": "Step B. Forward Common Event Format (CEF) logs to Syslog agent", - "description": "Contact WireX support (https://wirexsystems.com/contact-us/) in order to configure your NFP solution to send Syslog messages in CEF format to the proxy machine. Make sure that they central manager can send the logs to port 514 TCP on the machine's IP address.", - "instructions": [] + "description": "Contact WireX support (https://wirexsystems.com/contact-us/) in order to configure your NFP solution to send Syslog messages in CEF format to the proxy machine. Make sure that they central manager can send the logs to port 514 TCP on the machine's IP address." + }, { "title": "Step C. Validate connection", @@ -757,13 +757,13 @@ "instructionSteps": [ { "title": "Step A. Configure the Common Event Format (CEF) via AMA data connector", - "description": "_Note:- CEF logs are collected only from Linux Agents_\n\n1. Navigate to Microsoft Sentinel workspace ---> configuration ---> Data connector blade .\n\n2. Search for 'Common Event Format (CEF) via AMA' data connector and open it.\n\n3. Check If there is no existing DCR configured to collect required facility of logs, Create a new DCR (Data Collection Rule)\n\n\t_Note:- It is recommended to install minimum 1.27 version of AMA agent [Learn more](https://learn.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal ) and ensure there is no duplicate DCR as it can cause log duplicacy_\n\n4. Run the command provided in the CEF via AMA data connector page to configure the CEF collector on the machine", - "instructions": [] + "description": "_Note:- CEF logs are collected only from Linux Agents_\n\n1. Navigate to Microsoft Sentinel workspace ---> configuration ---> Data connector blade .\n\n2. Search for 'Common Event Format (CEF) via AMA' data connector and open it.\n\n3. Check If there is no existing DCR configured to collect required facility of logs, Create a new DCR (Data Collection Rule)\n\n\t_Note:- It is recommended to install minimum 1.27 version of AMA agent [Learn more](https://learn.microsoft.com/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal ) and ensure there is no duplicate DCR as it can cause log duplicacy_\n\n4. Run the command provided in the CEF via AMA data connector page to configure the CEF collector on the machine" + }, { "title": "Step B. Forward Common Event Format (CEF) logs to Syslog agent", - "description": "Contact WireX support (https://wirexsystems.com/contact-us/) in order to configure your NFP solution to send Syslog messages in CEF format to the proxy machine. Make sure that they central manager can send the logs to port 514 TCP on the machine's IP address.", - "instructions": [] + "description": "Contact WireX support (https://wirexsystems.com/contact-us/) in order to configure your NFP solution to send Syslog messages in CEF format to the proxy machine. Make sure that they central manager can send the logs to port 514 TCP on the machine's IP address." + }, { "title": "Step C. Validate connection", @@ -803,7 +803,7 @@ "contentSchemaVersion": "3.0.0", "displayName": "WireX Network Forensics Platform", "publisherDisplayName": "WireX Systems", - "descriptionHtml": "

Note: There may be known issues pertaining to this Solution, please refer to them before installing.

\n

The WireX Systems solution allows custom dashboards and workflows during forensic investigation integrated with Microsoft Sentinel.

\n
    \n
  1. WireX Network Forensics Platform via AMA - This data connector helps in ingesting OSSEC logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent here. Microsoft recommends using this Data Connector.

    \n
  2. \n
  3. WireX Network Forensics Platform via Legacy Agent - This data connector helps in ingesting WireX Network Forensics Platform logs into your Log Analytics Workspace using the legacy Log Analytics agent.

    \n
  4. \n
\n

NOTE: Microsoft recommends installation of WireX Network Forensics Platform via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by Aug 31, 2024, and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost more details.

\n

Data Connectors: 2

\n

Learn more about Microsoft Sentinel | Learn more about Solutions

\n", + "descriptionHtml": "

Note: There may be known issues pertaining to this Solution, please refer to them before installing.

\n

The WireX Systems solution allows custom dashboards and workflows during forensic investigation integrated with Microsoft Sentinel.

\n
    \n
  1. WireX Network Forensics Platform via AMA - This data connector helps in ingesting WireX Network Forensics Platform logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent here. Microsoft recommends using this Data Connector.

    \n
  2. \n
  3. WireX Network Forensics Platform via Legacy Agent - This data connector helps in ingesting WireX Network Forensics Platform logs into your Log Analytics Workspace using the legacy Log Analytics agent.

    \n
  4. \n
\n

NOTE: Microsoft recommends installation of WireX Network Forensics Platform via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by Aug 31, 2024, and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost more details.

\n

Data Connectors: 2

\n

Learn more about Microsoft Sentinel | Learn more about Solutions

\n", "contentKind": "Solution", "contentProductId": "[variables('_solutioncontentProductId')]", "id": "[variables('_solutioncontentProductId')]", diff --git a/Solutions/WireX Network Forensics Platform/ReleaseNotes.md b/Solutions/WireX Network Forensics Platform/ReleaseNotes.md new file mode 100644 index 00000000000..d0c2e90f791 --- /dev/null +++ b/Solutions/WireX Network Forensics Platform/ReleaseNotes.md @@ -0,0 +1,5 @@ +| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** | +|-------------|--------------------------------|------------------------------------------------------------------------| +| 3.0.0 | 05-09-2023 | Addition of new WireX Network Forensics Platform **Data Connector** | | + +