Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cisco Umbrella Connector missing updated Firewall Logs folder name #8788

Closed
wtcdwclark opened this issue Aug 15, 2023 · 34 comments
Closed

Cisco Umbrella Connector missing updated Firewall Logs folder name #8788

wtcdwclark opened this issue Aug 15, 2023 · 34 comments
Assignees
Labels
Connector Connector specialty review needed

Comments

@wtcdwclark
Copy link

wtcdwclark commented Aug 15, 2023

Discovered the Cisco Umbrella Connector was not pulling in my Cisco_Umbrella_cloudfirewall_CL logs:
image

Looking at the code, it is looking for a folder named "cloudfirewalllogs" or "cdfwlogs":
image

When browsing my S3 bucket, the folder is now called "firewalllogs":
image

According to the Cisco Umbrealla log documentation, they are now stored in "firewalllogs": https://docs.umbrella.com/umbrella-user-guide/docs/log-format-and-versioning
image

I believe the code should be updated to include the new firewall log folder name.

@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

1 similar comment
@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@v-sudkharat v-sudkharat added the Connector Connector specialty review needed label Aug 16, 2023
@v-sudkharat v-sudkharat self-assigned this Aug 16, 2023
@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

1 similar comment
@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@v-sudkharat
Copy link
Contributor

Hi @wtcdwclark, thanks for flagging this, we will soon get back to you on this. Thanks!

@v-rbajaj
Copy link
Contributor

We are investigating on this issue, we will soon get back to you.

@wtcdwclark
Copy link
Author

@v-sudkharat or @v-rbajaj Is there any update on this?

@v-rbajaj
Copy link
Contributor

v-rbajaj commented Sep 13, 2023

Hi @wtcdwclark, PR will be raised by 18 Sep 2023.

@v-rbajaj
Copy link
Contributor

Hi @wtcdwclark, sorry for the delay, we have raised this PR #9077 for this issue. We are currently testing the DC, once that is done we will let you know.

@wtcdwclark
Copy link
Author

wtcdwclark commented Sep 27, 2023 via email

@v-rbajaj
Copy link
Contributor

v-rbajaj commented Sep 27, 2023

Hi @wtcdwclark, testing is still progress, we will update you once we are done with testing..

@v-rbajaj
Copy link
Contributor

v-rbajaj commented Oct 5, 2023

Hi @wtcdwclark, sorry for delay, testing of the parser is still progress, we get back to by 10 Oct 2023

@v-rbajaj
Copy link
Contributor

Hi @wtcdwclark, sorry for delay, testing of the parser is still progress, we get back to by 20 Oct 2023

@v-rbajaj
Copy link
Contributor

Hi @wtcdwclark, sorry for delay, testing of the parser is still progress, we get back to by 31 Oct 2023

@v-rbajaj
Copy link
Contributor

v-rbajaj commented Nov 1, 2023

Hi @wtcdwclark, sorry for delay, testing of the parser is still progress, we get back to by 03 Nov 2023

@v-rbajaj
Copy link
Contributor

v-rbajaj commented Nov 3, 2023

Hi @wtcdwclark, sorry for delay, testing of the parser is still progress, we get back to by 08 Nov 2023

@v-rbajaj
Copy link
Contributor

v-rbajaj commented Nov 8, 2023

Hi @wtcdwclark, testing is still in progress, will get back to you by 10 Nov 2023

@v-rbajaj
Copy link
Contributor

Hi @wtcdwclark, testing is still in progress, will get back to you by 16 Nov 2023

@v-muuppugund
Copy link
Contributor

Hi @wtcdwclark PR(#9077) review is in progress and will get back to you by 20Nov23

@v-rbajaj
Copy link
Contributor

Hi @wtcdwclark,
Could you please update the WEBSITE_RUN_FROM_PACKAGE with the following URL in the function app:
image

URL: https://github.com/Azure/Azure-Sentinel/raw/4440d968a5b550fd94badfbc3dc30c60d3448f30/Solutions/CiscoUmbrella/Data%20Connectors/CiscoUmbrellaConn.zip

After updating, kindly restart the Function App and check if the issue persists. If this resolves the issue, we can proceed to merge the changes to the master branch.

@v-muuppugund
Copy link
Contributor

Hi @wtcdwclark Could you please check confirm after performing the above steps

@wtcdwclark
Copy link
Author

wtcdwclark commented Nov 20, 2023 via email

@wtcdwclark
Copy link
Author

wtcdwclark commented Nov 20, 2023 via email

@v-muuppugund
Copy link
Contributor

v-muuppugund commented Nov 20, 2023

Hi @wtcdwclark ,Will revalidate the issue resolution and get back to you with an update,Thanks.

@v-rbajaj
Copy link
Contributor

Hi @wtcdwclark, thanks for confirming, need to check and get back to you by 28 Nov 2023.

@v-rbajaj
Copy link
Contributor

Hi @wtcdwclark, we are investigating on this and will get back to you by 28 Nov 2023.

@v-rbajaj
Copy link
Contributor

Hi @wtcdwclark, we are still investigating on this and will get back to you by 04 Dec 2023

@v-rbajaj
Copy link
Contributor

v-rbajaj commented Dec 5, 2023

Hi @wtcdwclark, we are still investigating on this and will get back to you by 07 Dec 2023

@v-rbajaj
Copy link
Contributor

Hi @wtcdwclark,
We have made some more minor changes.
Could you please update the WEBSITE_RUN_FROM_PACKAGE with the following URL in the function app, just like last time?

URL:
https://github.com/Azure/Azure-Sentinel/raw/49ed35a71dae54e3173eb0d6edeaf9f18c53caab/Solutions/CiscoUmbrella/Data%20Connectors/CiscoUmbrellaConn.zip

After updating, kindly restart the Function App and check if the issue persists. If this resolves the issue, we can proceed to merge the changes to the master branch.

@wtcdwclark
Copy link
Author

wtcdwclark commented Dec 11, 2023 via email

@v-sudkharat v-sudkharat assigned v-muuppugund and unassigned v-rbajaj Dec 13, 2023
@v-amolpatil v-amolpatil removed their assignment Dec 14, 2023
@v-muuppugund
Copy link
Contributor

@wtcdwclark Thanks for confirmation ,we are closing the issue, If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation

@wtcdwclark
Copy link
Author

wtcdwclark commented Dec 15, 2023 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants