Skip to content

Commit 7736724

Browse files
authored
Merge pull request #11690 from Azure/v-rusraut/ApacheLog4j-ICM-587873612
Update UserAgentSearch_log4j.yaml
2 parents cb0c5b5 + cc16fdc commit 7736724

File tree

5 files changed

+97
-96
lines changed

5 files changed

+97
-96
lines changed

Solutions/Apache Log4j Vulnerability Detection/Analytic Rules/UserAgentSearch_log4j.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@ query: |
5959
(AzureDiagnostics
6060
| where Category in ("FrontdoorWebApplicationFirewallLog", "FrontdoorAccessLog", "ApplicationGatewayFirewallLog", "ApplicationGatewayAccessLog")
6161
| where userAgent_s has_any (UserAgentString) or userAgent_s matches regex UARegex
62-
| summarize StartTime = min(TimeGenerated), EndTime = max(TimeGenerated) by UserAgent = userAgent_s, SourceIP = column_ifexists("clientIp_s",clientIP_s), Type, column_ifexists("originalHost_s",host_s), Url = requestUri_s, HttpStatus = column_ifexists("httpStatusDetails_s",httpStatus_d), column_ifexists("transactionId_g",trackingReference_s), ruleName_s, ResourceType, ResourceId
62+
| summarize StartTime = min(TimeGenerated), EndTime = max(TimeGenerated) by UserAgent = userAgent_s, SourceIP = column_ifexists("clientIp_s",clientIP_s), Type, column_ifexists("originalHost_s",host_s), Url = requestUri_s, HttpStatus = column_ifexists("httpStatusDetails_s",httpStatus_d), column_ifexists("trackingReference_s",transactionId_g), ruleName_s, ResourceType, ResourceId
6363
),
6464
(
6565
W3CIISLog
@@ -97,5 +97,5 @@ entityMappings:
9797
fieldMappings:
9898
- identifier: Name
9999
columnName: Account
100-
version: 1.0.8
100+
version: 1.0.9
101101
kind: Scheduled

Solutions/Apache Log4j Vulnerability Detection/Data/Solution_Log4j.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@
5050
],
5151
"BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Apache Log4j Vulnerability Detection",
5252
"Metadata": "SolutionMetadata.json",
53-
"Version": "3.0.5",
53+
"Version": "3.0.6",
5454
"TemplateSpec": true,
55-
"Is1Pconnector": true
55+
"StaticDataConnector": true
5656
}
42.9 KB
Binary file not shown.

0 commit comments

Comments
 (0)