Skip to content

Commit a3da44d

Browse files
authored
Merge pull request #11193 from nipun-crestdatasystem/InfobloxSolutionPublishErrorFixes
Adding infoblox solution publishing fixes
2 parents 39e7320 + 4e0057d commit a3da44d

File tree

4 files changed

+31
-29
lines changed

4 files changed

+31
-29
lines changed
8 Bytes
Binary file not shown.

Solutions/Infoblox/Package/mainTemplate.json

Lines changed: 30 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@
4848
"variables": {
4949
"_solutionName": "Infoblox",
5050
"_solutionVersion": "3.0.0",
51-
"solutionId": "infoblox.infoblox-sentinel",
51+
"solutionId": "infoblox.infoblox-app-for-microsoft-sentinel",
5252
"_solutionId": "[variables('solutionId')]",
5353
"uiConfigId1": "InfobloxDataConnector",
5454
"_uiConfigId1": "[variables('uiConfigId1')]",
@@ -302,7 +302,9 @@
302302
"playbookId17": "[resourceId('Microsoft.Logic/workflows', variables('playbookContentId17'))]",
303303
"playbookTemplateSpecName17": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',concat(parameters('workspace'),'-pl-',uniquestring(variables('_playbookContentId17'))))]",
304304
"_playbookcontentProductId17": "[concat(take(variables('_solutionId'),50),'-','pl','-', uniqueString(concat(variables('_solutionId'),'-','Playbook','-',variables('_playbookContentId17'),'-', variables('playbookVersion17'))))]",
305-
"_solutioncontentProductId": "[concat(take(variables('_solutionId'),50),'-','sl','-', uniqueString(concat(variables('_solutionId'),'-','Solution','-',variables('_solutionId'),'-', variables('_solutionVersion'))))]"
305+
"_solutioncontentProductId": "[concat(take(variables('_solutionId'),50),'-','sl','-', uniqueString(concat(variables('_solutionId'),'-','Solution','-',variables('_solutionId'),'-', variables('_solutionVersion'))))]",
306+
"InfobloxInsightID": "InfobloxInsightID",
307+
"_Infoblox_Insight_ID": "[variables('InfobloxInsightID')]"
306308
},
307309
"resources": [
308310
{
@@ -3283,10 +3285,10 @@
32833285
"status": "Available",
32843286
"requiredDataConnectors": [
32853287
{
3286-
"connectorId": "InfobloxSOCInsightsDataConnector_API",
32873288
"dataTypes": [
32883289
"InfobloxInsight"
3289-
]
3290+
],
3291+
"connectorId": "InfobloxSOCInsightsDataConnector_API"
32903292
}
32913293
],
32923294
"tactics": [
@@ -3298,16 +3300,15 @@
32983300
],
32993301
"entityMappings": [
33003302
{
3301-
"entityType": "SecurityGroup",
33023303
"fieldMappings": [
33033304
{
33043305
"columnName": "InfobloxInsightID",
33053306
"identifier": "ObjectGuid"
33063307
}
3307-
]
3308+
],
3309+
"entityType": "SecurityGroup"
33083310
},
33093311
{
3310-
"entityType": "Malware",
33113312
"fieldMappings": [
33123313
{
33133314
"columnName": "ThreatClass",
@@ -3317,29 +3318,30 @@
33173318
"columnName": "ThreatProperty",
33183319
"identifier": "Category"
33193320
}
3320-
]
3321+
],
3322+
"entityType": "Malware"
33213323
}
33223324
],
33233325
"eventGroupingSettings": {
33243326
"aggregationKind": "AlertPerResult"
33253327
},
33263328
"customDetails": {
3327-
"UnblockedHits": "NotBlockedCount",
3329+
"Status": "Status",
33283330
"Severity": "Priority",
3331+
"PersistentDate": "PersistentDate",
3332+
"BlockedHits": "BlockedCount",
33293333
"FirstSeen": "FirstSeen",
33303334
"SpreadingDate": "SpreadingDate",
33313335
"LastSeen": "LastSeen",
33323336
"FeedSource": "FeedSource",
3333-
"Status": "Status",
3334-
"BlockedHits": "BlockedCount",
3335-
"InfobloxInsightID": "InfobloxInsightID",
3337+
"InfobloxInsightID": "[variables('_Infoblox_Insight_ID')]",
33363338
"TotalHits": "EventsCount",
3337-
"PersistentDate": "PersistentDate"
3339+
"UnblockedHits": "NotBlockedCount"
33383340
},
33393341
"alertDetailsOverride": {
3340-
"alertDescriptionFormat": "Observed via API. {{ThreatFamily}}. Last Observation: {{LastSeen}}",
3342+
"alertDisplayNameFormat": "Infoblox - SOC Insight - {{ThreatClass}} {{ThreatProperty}}",
33413343
"alertSeverityColumnName": "IncidentSeverity",
3342-
"alertDisplayNameFormat": "Infoblox - SOC Insight - {{ThreatClass}} {{ThreatProperty}}"
3344+
"alertDescriptionFormat": "Observed via API. {{ThreatFamily}}. Last Observation: {{LastSeen}}"
33433345
},
33443346
"incidentConfiguration": {
33453347
"createIncident": true
@@ -3423,16 +3425,16 @@
34233425
"status": "Available",
34243426
"requiredDataConnectors": [
34253427
{
3426-
"connectorId": "InfobloxSOCInsightsDataConnector_Legacy",
34273428
"dataTypes": [
34283429
"CommonSecurityLog (InfobloxCDC_SOCInsights)"
3429-
]
3430+
],
3431+
"connectorId": "InfobloxSOCInsightsDataConnector_Legacy"
34303432
},
34313433
{
3432-
"connectorId": "InfobloxSOCInsightsDataConnector_AMA",
34333434
"dataTypes": [
34343435
"CommonSecurityLog (InfobloxCDC_SOCInsights)"
3435-
]
3436+
],
3437+
"connectorId": "InfobloxSOCInsightsDataConnector_AMA"
34363438
}
34373439
],
34383440
"tactics": [
@@ -3444,16 +3446,15 @@
34443446
],
34453447
"entityMappings": [
34463448
{
3447-
"entityType": "SecurityGroup",
34483449
"fieldMappings": [
34493450
{
34503451
"columnName": "InfobloxInsightID",
34513452
"identifier": "ObjectGuid"
34523453
}
3453-
]
3454+
],
3455+
"entityType": "SecurityGroup"
34543456
},
34553457
{
3456-
"entityType": "Malware",
34573458
"fieldMappings": [
34583459
{
34593460
"columnName": "ThreatClass",
@@ -3463,24 +3464,25 @@
34633464
"columnName": "ThreatProperty",
34643465
"identifier": "Category"
34653466
}
3466-
]
3467+
],
3468+
"entityType": "Malware"
34673469
}
34683470
],
34693471
"eventGroupingSettings": {
34703472
"aggregationKind": "AlertPerResult"
34713473
},
34723474
"customDetails": {
3475+
"Status": "Status",
34733476
"UnblockedHits": "NotBlockedCount",
3477+
"BlockedHits": "BlockedCount",
34743478
"TotalHits": "EventsCount",
34753479
"FeedSource": "FeedSource",
3476-
"Status": "Status",
3477-
"BlockedHits": "BlockedCount",
3478-
"InfobloxInsightID": "InfobloxInsightID"
3480+
"InfobloxInsightID": "[variables('_Infoblox_Insight_ID')]"
34793481
},
34803482
"alertDetailsOverride": {
3481-
"alertDescriptionFormat": "Observed via CDC. {{ThreatFamily}}. {{Message}}",
3483+
"alertDisplayNameFormat": "Infoblox - SOC Insight - {{ThreatClass}} {{ThreatProperty}}",
34823484
"alertSeverityColumnName": "IncidentSeverity",
3483-
"alertDisplayNameFormat": "Infoblox - SOC Insight - {{ThreatClass}} {{ThreatProperty}}"
3485+
"alertDescriptionFormat": "Observed via CDC. {{ThreatFamily}}. {{Message}}"
34843486
},
34853487
"incidentConfiguration": {
34863488
"createIncident": true
File renamed without changes.

Solutions/Infoblox/SolutionMetadata.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"publisherId": "infoblox",
3-
"offerId": "infoblox-sentinel",
3+
"offerId": "infoblox-app-for-microsoft-sentinel",
44
"firstPublishDate": "2024-07-15",
55
"lastPublishDate": "2024-07-15",
66
"providers": [

0 commit comments

Comments
 (0)