Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Repackage - Ubiquiti UniFi #11519

Merged
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand All @@ -33,5 +30,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down Expand Up @@ -39,5 +36,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down Expand Up @@ -35,5 +32,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down Expand Up @@ -42,5 +39,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand All @@ -32,5 +29,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down Expand Up @@ -35,5 +32,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand All @@ -31,5 +28,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand All @@ -31,5 +28,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down Expand Up @@ -36,5 +33,5 @@ entityMappings:
fieldMappings:
- identifier: FullName
columnName: HostCustomEntity
version: 1.0.1
version: 1.0.2
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@ description: |
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand All @@ -30,5 +27,5 @@ entityMappings:
fieldMappings:
- identifier: Address
columnName: IPCustomEntity
version: 1.0.2
version: 1.0.3
kind: Scheduled
7 changes: 2 additions & 5 deletions Solutions/Ubiquiti UniFi/Data/Solution_Ubiquiti UniFi.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"Name": "Ubiquiti UniFi",
"Author": "Microsoft - support@microsoft.com",
"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/Ubiquiti%20UniFi/Data%20Connectors/Logo/ubiquiti.svg\" width=\"75px\" height=\"75px\">",
"Description": "The [Ubiquiti UniFi](https://www.ui.com/) solution provides the capability to ingest [Ubiquiti UniFi firewall, dns, ssh, AP events](https://help.ui.com/hc/articles/204959834-UniFi-How-to-View-Log-Files) into Microsoft Sentinel.\n\n This solution is dependent on the Custom logs via AMA connector to collect the logs. The Custom logs solution will be installed as part of this solution installation.\n\n **NOTE**: Microsoft recommends installation of Custom logs via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by Aug 31, 2024. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).",
"Description": "The [Ubiquiti UniFi](https://www.ui.com/) solution provides the capability to ingest [Ubiquiti UniFi firewall, dns, ssh, AP events](https://help.ui.com/hc/articles/204959834-UniFi-How-to-View-Log-Files) into Microsoft Sentinel.\n\n This solution is dependent on the Custom logs via AMA connector to collect the logs. The Custom logs solution will be installed as part of this solution installation.\n\n **NOTE**: Microsoft recommends installation of Custom logs via AMA Connector. Legacy connector uses the Log Analytics agent which were deprecated on **Aug 31, 2024.** Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).",
"Workbooks": [
"Workbooks/Ubiquiti.json"
],
Expand All @@ -18,9 +18,6 @@
"Hunting Queries/UbiquitiUnusualSubdomains.yaml",
"Hunting Queries/UbiquitiVulnerableDevices.yaml"
],
"Data Connectors": [
"Data Connectors/Connector_Ubiquiti_agent.json"
],
"Analytic Rules": [
"Analytic Rules/UbiquitiCryptominer.yaml",
"Analytic Rules/UbiquitiDestinationInTiList.yaml",
Expand All @@ -40,7 +37,7 @@
"azuresentinel.azure-sentinel-solution-customlogsviaama"
],
"BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Ubiquiti UniFi",
"Version": "3.0.2",
"Version": "3.0.3",
"Metadata": "SolutionMetadata.json",
"TemplateSpec": true,
"Is1Pconnector": false
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query shows failed DNS requests due to timeout.'
severity: Medium
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query shows list of unaccounted internal DNS servers.'
severity: Medium
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query shows list of least used internal destination ports.'
severity: Medium
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query shows list of top destinations connections to which were blocked by firewall.'
severity: Medium
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query shows list of top blocked connections to external services.'
severity: Medium
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query shows list of top blocked connections to internal services.'
severity: Medium
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query shows list of top sources with blocked connections.'
severity: Medium
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query shows list of top triggered firewall rules.'
severity: Medium
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query counts the number of unique subdomains for each TLD.'
severity: Medium
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,6 @@ description: |
'Query shows list of devices (APs) which do not have the latest version of firmware installed.'
severity: Medium
requiredDataConnectors:
- connectorId: UbiquitiUnifi
dataTypes:
- UbiquitiAuditEvent
- connectorId: CustomLogsAma
dataTypes:
- Ubiquiti_CL
Expand Down
Binary file added Solutions/Ubiquiti UniFi/Package/3.0.3.zip
Binary file not shown.
Loading
Loading