|
1298 | 1298 | ], |
1299 | 1299 | "properties": { |
1300 | 1300 | "contentId": "[variables('_dataConnectorContentIdConnectorDefinition1')]", |
1301 | | - "displayName": "Cisco Secure Endpoint (via Codeless Connector Framework)", |
| 1301 | + "displayName": "Cisco Secure Endpoint (via Codeless Connector Framework) (Preview)", |
1302 | 1302 | "contentKind": "DataConnector", |
1303 | 1303 | "mainTemplate": { |
1304 | 1304 | "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", |
|
1315 | 1315 | "properties": { |
1316 | 1316 | "connectorUiConfig": { |
1317 | 1317 | "id": "CiscoSecureEndpointLogsCCPDefinition", |
1318 | | - "title": "Cisco Secure Endpoint (via Codeless Connector Framework)", |
| 1318 | + "title": "Cisco Secure Endpoint (via Codeless Connector Framework) (Preview)", |
1319 | 1319 | "publisher": "Microsoft", |
1320 | 1320 | "descriptionMarkdown": "The Cisco Secure Endpoint (formerly AMP for Endpoints) data connector provides the capability to ingest Cisco Secure Endpoint [audit logs](https://developer.cisco.com/docs/secure-endpoint/auditlog/) and [events](https://developer.cisco.com/docs/secure-endpoint/v1-api-reference-event/) into Microsoft Sentinel.", |
1321 | 1321 | "graphQueries": [ |
|
2597 | 2597 | "properties": { |
2598 | 2598 | "connectorUiConfig": { |
2599 | 2599 | "id": "CiscoSecureEndpointLogsCCPDefinition", |
2600 | | - "title": "Cisco Secure Endpoint (via Codeless Connector Framework)", |
| 2600 | + "title": "Cisco Secure Endpoint (via Codeless Connector Framework) (Preview)", |
2601 | 2601 | "publisher": "Microsoft", |
2602 | 2602 | "descriptionMarkdown": "The Cisco Secure Endpoint (formerly AMP for Endpoints) data connector provides the capability to ingest Cisco Secure Endpoint [audit logs](https://developer.cisco.com/docs/secure-endpoint/auditlog/) and [events](https://developer.cisco.com/docs/secure-endpoint/v1-api-reference-event/) into Microsoft Sentinel.", |
2603 | 2603 | "graphQueries": [ |
|
2807 | 2807 | ], |
2808 | 2808 | "properties": { |
2809 | 2809 | "contentId": "[variables('_dataConnectorContentIdConnections1')]", |
2810 | | - "displayName": "Cisco Secure Endpoint (via Codeless Connector Framework)", |
| 2810 | + "displayName": "Cisco Secure Endpoint (via Codeless Connector Framework) (Preview)", |
2811 | 2811 | "contentKind": "ResourcesDataConnector", |
2812 | 2812 | "mainTemplate": { |
2813 | 2813 | "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", |
|
2822 | 2822 | "type": "securestring" |
2823 | 2823 | }, |
2824 | 2824 | "connectorDefinitionName": { |
2825 | | - "defaultValue": "Cisco Secure Endpoint (via Codeless Connector Framework)", |
| 2825 | + "defaultValue": "Cisco Secure Endpoint (via Codeless Connector Framework) (Preview)", |
2826 | 2826 | "type": "securestring", |
2827 | 2827 | "minLength": 1 |
2828 | 2828 | }, |
|
3231 | 3231 | "title": "[DEPRECATED] Cisco Secure Endpoint (AMP) (using Azure Functions)", |
3232 | 3232 | "publisher": "Cisco", |
3233 | 3233 | "descriptionMarkdown": "The Cisco Secure Endpoint (formerly AMP for Endpoints) data connector provides the capability to ingest Cisco Secure Endpoint [audit logs](https://api-docs.amp.cisco.com/api_resources/AuditLog?api_host=api.amp.cisco.com&api_version=v1) and [events](https://api-docs.amp.cisco.com/api_actions/details?api_action=GET+%2Fv1%2Fevents&api_host=api.amp.cisco.com&api_resource=Event&api_version=v1) into Microsoft Sentinel.\n\n<p><span style='color:red; font-weight:bold;'>NOTE</span>: This data connector has been deprecated, consider moving to the CCF data connector available in the solution which replaces ingestion via the <a href='https://learn.microsoft.com/en-us/azure/azure-monitor/logs/custom-logs-migrate' style='color:#1890F1;'>deprecated HTTP Data Collector API</a>.</p>", |
3234 | | - "graphQueries": [ |
3235 | | - { |
3236 | | - "metricName": "Cisco Secure Endpoint logs", |
3237 | | - "legend": "CiscoSecureEndpoint_CL", |
3238 | | - "baseQuery": "CiscoSecureEndpoint_CL" |
3239 | | - } |
3240 | | - ], |
3241 | | - "dataTypes": [ |
3242 | | - { |
3243 | | - "name": "CiscoSecureEndpoint_CL", |
3244 | | - "lastDataReceivedQuery": "CiscoSecureEndpoint_CL\n | summarize Time = max(TimeGenerated)\n | where isnotempty(Time)" |
3245 | | - } |
3246 | | - ], |
| 3234 | + "graphQueries": { |
| 3235 | + "metricName": "Cisco Secure Endpoint logs", |
| 3236 | + "legend": "CiscoSecureEndpoint_CL", |
| 3237 | + "baseQuery": "CiscoSecureEndpoint_CL" |
| 3238 | + }, |
| 3239 | + "dataTypes": { |
| 3240 | + "name": "CiscoSecureEndpoint_CL", |
| 3241 | + "lastDataReceivedQuery": "CiscoSecureEndpoint_CL\n | summarize Time = max(TimeGenerated)\n | where isnotempty(Time)" |
| 3242 | + }, |
3247 | 3243 | "connectivityCriterias": [ |
3248 | 3244 | { |
3249 | 3245 | "type": "IsConnectedQuery", |
|
3252 | 3248 | ] |
3253 | 3249 | } |
3254 | 3250 | ], |
3255 | | - "sampleQueries": [ |
3256 | | - { |
3257 | | - "description": "All Cisco Secure Endpoint logs", |
3258 | | - "query": "CiscoSecureEndpoint_CL\n| sort by TimeGenerated desc" |
3259 | | - } |
3260 | | - ], |
| 3251 | + "sampleQueries": { |
| 3252 | + "description": "All Cisco Secure Endpoint logs", |
| 3253 | + "query": "CiscoSecureEndpoint_CL\n| sort by TimeGenerated desc" |
| 3254 | + }, |
3261 | 3255 | "availability": { |
3262 | 3256 | "status": 1, |
3263 | 3257 | "isPreview": false |
|
0 commit comments