Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Contributed a new Azure Sentinel solution for Torq which includes a n… #11383

Merged
merged 10 commits into from
Nov 21, 2024

Conversation

acitatorq
Copy link
Contributor

…ew playbook

Required items, please complete

Change(s):

  • New Azure Sentinel Solution: Torq, which contains one playbook

Reason for Change(s):

  • New Azure Sentinel Solution: Torq.

Version Updated:

  • No

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

@acitatorq acitatorq requested review from a team as code owners November 6, 2024 19:29
@acitatorq
Copy link
Contributor Author

@microsoft-github-policy-service agree company="Torq"

@acitatorq
Copy link
Contributor Author

acitatorq commented Nov 6, 2024 via email

@v-prasadboke v-prasadboke added Solution Solution specialty review needed New Solution For new Solutions which are new to Microsoft Sentinel labels Nov 7, 2024
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"metadata": {
"title": "Notify Sentinel Incident Creation and Update to Torq Webhook",
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The playbook is missing with some properties in metadata
postdeployement
prerequisites
please go through this playbook once to check missing metadata properties
https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Recorded%20Future/Playbooks/Enrichment/RecordedFuture-IOC_Enrichment/azuredeploy.json

* Torq_Webhook_Auth_Header_Name: Enter the authentication header name for the Microsoft Sentinel Trigger integration previously created in Torq.
* Torq_Webhook_Auth_Header_Secret: Enter the authentication header secret for the Microsoft Sentinel Trigger integration previously created in Torq.

[![Deploy to Azure](https://aka.ms/deploytoazurebutton)](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSolutions%2FTorq%2FPlaybooks%2FPlaybooks%2FTorq-Sentinel-Incident-Trigger%2Fazuredeploy.json) [![Deploy to Azure](https://aka.ms/deploytoazuregovbutton)](https://portal.azure.us/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSolutions%2FTorq%2FPlaybooks%2FPlaybooks%2FTorq-Sentinel-Incident-Trigger%2Fazuredeploy.json)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

replace deploy to azure with
Deploy to Azure Gov
for gov links

@@ -0,0 +1,15 @@
{
"publisherId": "azuresentinel",
"offerId": "azure-sentinel-solution-torq",
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please confirm once if this solution is microsoft supported
In case if not
please change the publisher id and support details

@v-prasadboke
Copy link
Contributor

Hello @acitatorq, The solution is missing with input file which is located in data folder.
it is required to package the solution and contains basic details of the Solution

For Ref - https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Recorded%20Future/Data

@acitatorq
Copy link
Contributor Author

Thanks for your comments and advise @v-prasadboke, I have just updated the PR as per your instructions

@v-atulyadav v-atulyadav merged commit 314e408 into Azure:master Nov 21, 2024
33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
New Solution For new Solutions which are new to Microsoft Sentinel Solution Solution specialty review needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants