Skip to content

Commit 91365cc

Browse files
committed
Repackage - Cisco WSA
1 parent 325dc65 commit 91365cc

26 files changed

+98
-679
lines changed

Solutions/CiscoWSA/Analytic Rules/CiscoWSAAccessToUnwantedSite.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ description: |
55
severity: High
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CiscoWSA
9-
dataTypes:
10-
- CiscoWSAEvent
118
- connectorId: SyslogAma
129
datatypes:
1310
- Syslog
@@ -30,5 +27,5 @@ entityMappings:
3027
fieldMappings:
3128
- identifier: Name
3229
columnName: AccountCustomEntity
33-
version: 1.0.2
30+
version: 1.0.3
3431
kind: Scheduled

Solutions/CiscoWSA/Analytic Rules/CiscoWSADataExfiltration.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ description: |
55
severity: High
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CiscoWSA
9-
dataTypes:
10-
- CiscoWSAEvent
118
- connectorId: SyslogAma
129
datatypes:
1310
- Syslog
@@ -35,5 +32,5 @@ entityMappings:
3532
fieldMappings:
3633
- identifier: Name
3734
columnName: AccountCustomEntity
38-
version: 1.0.2
35+
version: 1.0.3
3936
kind: Scheduled

Solutions/CiscoWSA/Analytic Rules/CiscoWSAMultipleErrorsToUnwantedCategory.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CiscoWSA
9-
dataTypes:
10-
- CiscoWSAEvent
118
- connectorId: SyslogAma
129
datatypes:
1310
- Syslog
@@ -39,5 +36,5 @@ entityMappings:
3936
fieldMappings:
4037
- identifier: Name
4138
columnName: AccountCustomEntity
42-
version: 1.0.1
39+
version: 1.0.2
4340
kind: Scheduled

Solutions/CiscoWSA/Analytic Rules/CiscoWSAMultipleErrorsToUrl.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CiscoWSA
9-
dataTypes:
10-
- CiscoWSAEvent
118
- connectorId: SyslogAma
129
datatypes:
1310
- Syslog
@@ -35,5 +32,5 @@ entityMappings:
3532
fieldMappings:
3633
- identifier: Name
3734
columnName: AccountCustomEntity
38-
version: 1.0.1
35+
version: 1.0.2
3936
kind: Scheduled

Solutions/CiscoWSA/Analytic Rules/CiscoWSAMultipleInfectedFiles.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ description: |
55
severity: High
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CiscoWSA
9-
dataTypes:
10-
- CiscoWSAEvent
118
- connectorId: SyslogAma
129
datatypes:
1310
- Syslog
@@ -35,5 +32,5 @@ entityMappings:
3532
fieldMappings:
3633
- identifier: Name
3734
columnName: AccountCustomEntity
38-
version: 1.0.2
35+
version: 1.0.3
3936
kind: Scheduled

Solutions/CiscoWSA/Analytic Rules/CiscoWSAMultipleUnwantedFileTypes.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CiscoWSA
9-
dataTypes:
10-
- CiscoWSAEvent
118
- connectorId: SyslogAma
129
datatypes:
1310
- Syslog
@@ -35,5 +32,5 @@ entityMappings:
3532
fieldMappings:
3633
- identifier: Url
3734
columnName: UrlCustomEntity
38-
version: 1.0.1
35+
version: 1.0.2
3936
kind: Scheduled

Solutions/CiscoWSA/Analytic Rules/CiscoWSAProtocolAbuse.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CiscoWSA
9-
dataTypes:
10-
- CiscoWSAEvent
118
- connectorId: SyslogAma
129
datatypes:
1310
- Syslog
@@ -33,5 +30,5 @@ entityMappings:
3330
fieldMappings:
3431
- identifier: Name
3532
columnName: AccountCustomEntity
36-
version: 1.0.1
33+
version: 1.0.2
3734
kind: Scheduled

Solutions/CiscoWSA/Analytic Rules/CiscoWSAPublicIPSource.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CiscoWSA
9-
dataTypes:
10-
- CiscoWSAEvent
118
- connectorId: SyslogAma
129
datatypes:
1310
- Syslog
@@ -29,5 +26,5 @@ entityMappings:
2926
fieldMappings:
3027
- identifier: Address
3128
columnName: IPCustomEntity
32-
version: 1.0.1
29+
version: 1.0.2
3330
kind: Scheduled

Solutions/CiscoWSA/Analytic Rules/CiscoWSAUnexpectedFileType.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CiscoWSA
9-
dataTypes:
10-
- CiscoWSAEvent
118
- connectorId: SyslogAma
129
datatypes:
1310
- Syslog
@@ -35,5 +32,5 @@ entityMappings:
3532
fieldMappings:
3633
- identifier: Name
3734
columnName: AccountCustomEntity
38-
version: 1.0.1
35+
version: 1.0.2
3936
kind: Scheduled

Solutions/CiscoWSA/Analytic Rules/CiscoWSAUnexpectedUrl.yaml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ description: |
55
severity: Medium
66
status: Available
77
requiredDataConnectors:
8-
- connectorId: CiscoWSA
9-
dataTypes:
10-
- CiscoWSAEvent
118
- connectorId: SyslogAma
129
datatypes:
1310
- Syslog
@@ -33,5 +30,5 @@ entityMappings:
3330
fieldMappings:
3431
- identifier: Name
3532
columnName: AccountCustomEntity
36-
version: 1.0.1
33+
version: 1.0.2
3734
kind: Scheduled

0 commit comments

Comments
 (0)