.ods.opinsights.azure.us`.\n4. Once all application settings have been entered, click **Save**."
@@ -520,7 +520,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CrowdStrike Falcon Endpoint Protection data connector with template version 3.0.8",
+ "description": "CrowdStrike Falcon Endpoint Protection data connector with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('dataConnectorVersion2')]",
@@ -869,7 +869,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CrowdStrike Falcon Endpoint Protection data connector with template version 3.0.8",
+ "description": "CrowdStrike Falcon Endpoint Protection data connector with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('dataConnectorVersion3')]",
@@ -1253,7 +1253,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CrowdStrike Falcon Endpoint Protection data connector with template version 3.0.8",
+ "description": "CrowdStrike Falcon Endpoint Protection data connector with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('dataConnectorVersion4')]",
@@ -1586,7 +1586,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CrowdStrike Falcon Endpoint Protection data connector with template version 3.0.8",
+ "description": "CrowdStrike Falcon Endpoint Protection data connector with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('dataConnectorVersion5')]",
@@ -1917,7 +1917,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CrowdStrikeFalconEventStream Data Parser with template version 3.0.8",
+ "description": "CrowdStrikeFalconEventStream Data Parser with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('parserObject1').parserVersion1]",
@@ -2049,7 +2049,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CrowdstrikeReplicator Data Parser with template version 3.0.8",
+ "description": "CrowdstrikeReplicator Data Parser with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('parserObject2').parserVersion2]",
@@ -2181,7 +2181,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CrowdStrikeReplicatorV2 Data Parser with template version 3.0.8",
+ "description": "CrowdStrikeReplicatorV2 Data Parser with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('parserObject3').parserVersion3]",
@@ -2313,7 +2313,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CrowdStrikeFalconEndpointProtection Workbook with template version 3.0.8",
+ "description": "CrowdStrikeFalconEndpointProtection Workbook with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('workbookVersion1')]",
@@ -2401,7 +2401,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CriticalOrHighSeverityDetectionsByUser_AnalyticalRules Analytics Rule with template version 3.0.8",
+ "description": "CriticalOrHighSeverityDetectionsByUser_AnalyticalRules Analytics Rule with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('analyticRuleObject1').analyticRuleVersion1]",
@@ -2429,22 +2429,22 @@
"status": "Available",
"requiredDataConnectors": [
{
- "connectorId": "CrowdStrikeFalconEndpointProtection",
"dataTypes": [
"CommonSecurityLog"
- ]
+ ],
+ "connectorId": "CrowdStrikeFalconEndpointProtection"
},
{
- "connectorId": "CrowdStrikeFalconEndpointProtectionAma",
"dataTypes": [
"CommonSecurityLog"
- ]
+ ],
+ "connectorId": "CrowdStrikeFalconEndpointProtectionAma"
},
{
- "connectorId": "CefAma",
"dataTypes": [
"CommonSecurityLog"
- ]
+ ],
+ "connectorId": "CefAma"
}
],
"entityMappings": [
@@ -2542,7 +2542,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CriticalSeverityDetection_AnalyticalRules Analytics Rule with template version 3.0.8",
+ "description": "CriticalSeverityDetection_AnalyticalRules Analytics Rule with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('analyticRuleObject2').analyticRuleVersion2]",
@@ -2570,22 +2570,22 @@
"status": "Available",
"requiredDataConnectors": [
{
- "connectorId": "CrowdStrikeFalconEndpointProtection",
"dataTypes": [
"CommonSecurityLog"
- ]
+ ],
+ "connectorId": "CrowdStrikeFalconEndpointProtection"
},
{
- "connectorId": "CrowdStrikeFalconEndpointProtectionAma",
"dataTypes": [
"CommonSecurityLog"
- ]
+ ],
+ "connectorId": "CrowdStrikeFalconEndpointProtectionAma"
},
{
- "connectorId": "CefAma",
"dataTypes": [
"CommonSecurityLog"
- ]
+ ],
+ "connectorId": "CefAma"
}
],
"entityMappings": [
@@ -2683,7 +2683,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "CrowdStrike_Base Playbook with template version 3.0.8",
+ "description": "CrowdStrike_Base Playbook with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('playbookVersion1')]",
@@ -3060,7 +3060,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "Crowdstrike-EndpointEnrichment Playbook with template version 3.0.8",
+ "description": "Crowdstrike-EndpointEnrichment Playbook with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('playbookVersion2')]",
@@ -4515,7 +4515,7 @@
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
],
"properties": {
- "description": "Crowdstrike-ContainHost Playbook with template version 3.0.8",
+ "description": "Crowdstrike-ContainHost Playbook with template version 3.0.9",
"mainTemplate": {
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "[variables('playbookVersion3')]",
@@ -5630,12 +5630,12 @@
"apiVersion": "2023-04-01-preview",
"location": "[parameters('workspace-location')]",
"properties": {
- "version": "3.0.8",
+ "version": "3.0.9",
"kind": "Solution",
"contentSchemaVersion": "3.0.0",
"displayName": "CrowdStrike Falcon Endpoint Protection",
"publisherDisplayName": "Microsoft Sentinel, Microsoft Corporation",
- "descriptionHtml": "Note: Please refer to the following before installing the solution:
\n• Review the solution Release Notes
\n• There may be known issues pertaining to this Solution, please refer to them before installing.
\nThe CrowdStrike Falcon Endpoint Protection solution allows you to easily connect your CrowdStrike Falcon Event Stream with Microsoft Sentinel, to create custom dashboards, alerts, and improve investigation. This gives you more insight into your organization's endpoints and improves your security operation capabilities.
\n\n\nThis solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.
\nNOTE: Microsoft recommends installation of CEF via AMA Connector. The existing connectors are about to be deprecated by Aug 31, 2024.
\nData Connectors: 5, Parsers: 3, Workbooks: 1, Analytic Rules: 2, Playbooks: 3
\nLearn more about Microsoft Sentinel | Learn more about Solutions
\n",
+ "descriptionHtml": "Note: Please refer to the following before installing the solution:
\n• Review the solution Release Notes
\n• There may be known issues pertaining to this Solution, please refer to them before installing.
\nThe CrowdStrike Falcon Endpoint Protection solution allows you to easily connect your CrowdStrike Falcon Event Stream with Microsoft Sentinel, to create custom dashboards, alerts, and improve investigation. This gives you more insight into your organization's endpoints and improves your security operation capabilities.
\nThis solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.
\nNOTE: Microsoft recommends installation of CEF via AMA Connector. The existing connectors are about to be deprecated by Aug 31, 2024.
\nData Connectors: 5, Parsers: 3, Workbooks: 1, Analytic Rules: 2, Playbooks: 3
\nLearn more about Microsoft Sentinel | Learn more about Solutions
\n",
"contentKind": "Solution",
"contentProductId": "[variables('_solutioncontentProductId')]",
"id": "[variables('_solutioncontentProductId')]",
diff --git a/Solutions/CrowdStrike Falcon Endpoint Protection/ReleaseNotes.md b/Solutions/CrowdStrike Falcon Endpoint Protection/ReleaseNotes.md
index 52f0b05f19c..de279d00023 100644
--- a/Solutions/CrowdStrike Falcon Endpoint Protection/ReleaseNotes.md
+++ b/Solutions/CrowdStrike Falcon Endpoint Protection/ReleaseNotes.md
@@ -1,5 +1,6 @@
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
|-------------|--------------------------------|--------------------------------------------------------------------------------|
+| 3.0.9 | 20-09-2024 | Updated the python runtime version to 3.11 |
| 3.0.8 | 10-07-2024 | Deprecated **Data Connector** |
| 3.0.7 | 20-06-2024 | Shortlinks updated for **Data Connector** CrowdStrike Falcon Indicators of Compromise |
| 3.0.6 | 06-06-2024 | Renamed **Data Connector** *CrowdStrike Falcon Indicators of Compromise* to *CrowdStrike Falcon Adversary Intelligence* |