Skip to content

Commit 014e568

Browse files
authored
Merge pull request Azure#12911 from Veeam-Rnd-DataManagement/veeam-develop
Support Coveware API changes and fix dashboard drilldowns
2 parents 67ac6db + 13da262 commit 014e568

File tree

194 files changed

+6141
-4172
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

194 files changed

+6141
-4172
lines changed

Solutions/Veeam/Analytic Rules/Adding_User_or_Group_Failed.yaml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,15 +17,13 @@ triggerOperator: gt
1717
triggerThreshold: 0
1818
eventGroupingSettings:
1919
aggregationKind: AlertPerResult
20-
tactics:
21-
- DefenseEvasion
22-
relevantTechniques:
23-
- T1562
20+
tactics: []
21+
relevantTechniques: []
2422
query: "Veeam_GetSecurityEvents\n| where instanceId == 31210\n| project\n Date\
2523
\ = format_datetime(TimeGenerated, 'dd.MM.yyyy HH:mm'),\n DataSource = original_host,\n\
2624
\ EventId = instanceId,\n UserName = user,\n MessageDetails = Description,\n\
2725
\ Severity = SeverityDescription"
28-
version: 1.0.0
26+
version: 1.0.1
2927
kind: Scheduled
3028
customDetails:
3129
Date: Date

Solutions/Veeam/Analytic Rules/Application_Group_Deleted.yaml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,16 +17,14 @@ triggerOperator: gt
1717
triggerThreshold: 0
1818
eventGroupingSettings:
1919
aggregationKind: AlertPerResult
20-
tactics:
21-
- Impact
22-
relevantTechniques:
23-
- T1485
20+
tactics: []
21+
relevantTechniques: []
2422
query: "Veeam_GetSecurityEvents\n| where instanceId == 30500\n| extend Name = extract(\"\
2523
Name=\\\"([^\\\"]*)\\\"\", 1, SyslogMessage)\n| project\n Date = format_datetime(TimeGenerated,\
2624
\ 'dd.MM.yyyy HH:mm'),\n DataSource = original_host,\n EventId = instanceId,\n\
2725
\ UserName = user,\n [\"Application Group Name\"] = Name,\n MessageDetails\
2826
\ = Description,\n Severity = SeverityDescription"
29-
version: 1.0.0
27+
version: 1.0.1
3028
kind: Scheduled
3129
customDetails:
3230
Date: Date

Solutions/Veeam/Analytic Rules/Application_Group_Settings_Updated.yaml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,16 +17,14 @@ triggerOperator: gt
1717
triggerThreshold: 0
1818
eventGroupingSettings:
1919
aggregationKind: AlertPerResult
20-
tactics:
21-
- DefenseEvasion
22-
relevantTechniques:
23-
- T1562.001
20+
tactics: []
21+
relevantTechniques: []
2422
query: "Veeam_GetSecurityEvents\n| where instanceId == 30400\n| extend Name = extract(\"\
2523
Name=\\\"([^\\\"]*)\\\"\", 1, SyslogMessage)\n| project\n Date = format_datetime(TimeGenerated,\
2624
\ 'dd.MM.yyyy HH:mm'),\n DataSource = original_host,\n EventId = instanceId,\n\
2725
\ UserName = user,\n [\"Application Group Name\"] = Name,\n MessageDetails\
2826
\ = Description,\n Severity = SeverityDescription"
29-
version: 1.0.0
27+
version: 1.0.1
3028
kind: Scheduled
3129
customDetails:
3230
Date: Date

Solutions/Veeam/Analytic Rules/Archive_Repository_Deleted.yaml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,16 +17,14 @@ triggerOperator: gt
1717
triggerThreshold: 0
1818
eventGroupingSettings:
1919
aggregationKind: AlertPerResult
20-
tactics:
21-
- Impact
22-
relevantTechniques:
23-
- T1485
20+
tactics: []
21+
relevantTechniques: []
2422
query: "Veeam_GetSecurityEvents\n| where instanceId == 29900\n| extend Name = extract(\"\
2523
Name=\\\"([^\\\"]*)\\\"\", 1, SyslogMessage)\n| project\n Date = format_datetime(TimeGenerated,\
2624
\ 'dd.MM.yyyy HH:mm'),\n DataSource = original_host,\n EventId = instanceId,\n\
2725
\ [\"User Name\"] = user,\n [\"Object Name\"] = Name,\n MessageDetails\
2826
\ = Description,\n Severity = SeverityDescription"
29-
version: 1.0.0
27+
version: 1.0.1
3028
kind: Scheduled
3129
customDetails:
3230
Date: Date

Solutions/Veeam/Analytic Rules/Archive_Repository_Settings_Updated.yaml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,16 +17,14 @@ triggerOperator: gt
1717
triggerThreshold: 0
1818
eventGroupingSettings:
1919
aggregationKind: AlertPerResult
20-
tactics:
21-
- DefenseEvasion
22-
relevantTechniques:
23-
- T1562.001
20+
tactics: []
21+
relevantTechniques: []
2422
query: "Veeam_GetSecurityEvents\n| where instanceId == 29800\n| extend Name = extract(\"\
2523
Name=\\\"([^\\\"]*)\\\"\", 1, SyslogMessage)\n| project\n Date = format_datetime(TimeGenerated,\
2624
\ 'dd.MM.yyyy HH:mm'),\n DataSource = original_host,\n EventId = instanceId,\n\
2725
\ UserName = user,\n [\"Object Name\"] = Name,\n MessageDetails = Description,\n\
2826
\ Severity = SeverityDescription"
29-
version: 1.0.0
27+
version: 1.0.1
3028
kind: Scheduled
3129
customDetails:
3230
Date: Date

Solutions/Veeam/Analytic Rules/Attempt_to_Delete_Backup_Failed.yaml

Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -17,18 +17,14 @@ triggerOperator: gt
1717
triggerThreshold: 0
1818
eventGroupingSettings:
1919
aggregationKind: AlertPerResult
20-
tactics:
21-
- DefenseEvasion
22-
- Impact
23-
relevantTechniques:
24-
- T1562
25-
- T1490
20+
tactics: []
21+
relevantTechniques: []
2622
query: "Veeam_GetSecurityEvents\n| where instanceId == 41800\n| extend Endpoint =\
2723
\ extract(\"param2=\\\"([^\\\"]*)\\\"\", 1, SyslogMessage)\n| project\n Date\
2824
\ = format_datetime(TimeGenerated, 'dd.MM.yyyy HH:mm'),\n DataSource = original_host,\n\
2925
\ EventId = instanceId,\n [\"User Name\"] = user,\n [\"Endpoint\"] = Endpoint,\n\
3026
\ MessageDetails = Description,\n Severity = SeverityDescription"
31-
version: 1.0.0
27+
version: 1.0.1
3228
kind: Scheduled
3329
customDetails:
3430
Date: Date

Solutions/Veeam/Analytic Rules/Attempt_to_Update_Security_Object_Failed.yaml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -18,16 +18,14 @@ triggerOperator: gt
1818
triggerThreshold: 0
1919
eventGroupingSettings:
2020
aggregationKind: AlertPerResult
21-
tactics:
22-
- DefenseEvasion
23-
relevantTechniques:
24-
- T1562
21+
tactics: []
22+
relevantTechniques: []
2523
query: "Veeam_GetSecurityEvents\n| where instanceId == 41810\n| extend Endpoint =\
2624
\ extract(\"param2=\\\"([^\\\"]*)\\\"\", 1, SyslogMessage)\n| project\n Date\
2725
\ = format_datetime(TimeGenerated, 'dd.MM.yyyy HH:mm'),\n DataSource = original_host,\n\
2826
\ EventId = instanceId,\n [\"User Name\"] = user,\n [\"Endpoint\"] = Endpoint,\n\
2927
\ MessageDetails = Description,\n Severity = SeverityDescription"
30-
version: 1.0.0
28+
version: 1.0.1
3129
kind: Scheduled
3230
customDetails:
3331
Date: Date

Solutions/Veeam/Analytic Rules/Backup_Proxy_Deleted.yaml

Lines changed: 3 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -17,16 +17,13 @@ triggerOperator: gt
1717
triggerThreshold: 0
1818
eventGroupingSettings:
1919
aggregationKind: AlertPerResult
20-
tactics:
21-
- Impact
22-
relevantTechniques:
23-
- T1485
24-
- T1490
20+
tactics: []
21+
relevantTechniques: []
2522
query: "Veeam_GetSecurityEvents\n| where instanceId == 27900\n| project\n Date\
2623
\ = format_datetime(TimeGenerated, 'dd.MM.yyyy HH:mm'),\n DataSource = original_host,\n\
2724
\ EventId = instanceId,\n [\"User Name\"] = user,\n MessageDetails = Description,\n\
2825
\ Severity = SeverityDescription"
29-
version: 1.0.0
26+
version: 1.0.1
3027
kind: Scheduled
3128
customDetails:
3229
Date: Date

Solutions/Veeam/Analytic Rules/Backup_Repository_Deleted.yaml

Lines changed: 3 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -17,17 +17,14 @@ triggerOperator: gt
1717
triggerThreshold: 0
1818
eventGroupingSettings:
1919
aggregationKind: AlertPerResult
20-
tactics:
21-
- Impact
22-
relevantTechniques:
23-
- T1485
24-
- T1490
20+
tactics: []
21+
relevantTechniques: []
2522
query: "Veeam_GetSecurityEvents\n| where instanceId == 28200\n| extend Name = extract(\"\
2623
Name=\\\"(?<Name>[^\\\"]*)\\\"\", 1, SyslogMessage)\n| project\n Date = format_datetime(TimeGenerated,\
2724
\ 'dd.MM.yyyy HH:mm'),\n DataSource = original_host,\n EventId = instanceId,\n\
2825
\ UserName = user,\n [\"Object Name\"] = Name,\n MessageDetails = Description,\n\
2926
\ Severity = SeverityDescription"
30-
version: 1.0.0
27+
version: 1.0.1
3128
kind: Scheduled
3229
customDetails:
3330
Date: Date

Solutions/Veeam/Analytic Rules/Backup_Repository_Settings_Updated.yaml

Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -17,19 +17,15 @@ triggerOperator: gt
1717
triggerThreshold: 0
1818
eventGroupingSettings:
1919
aggregationKind: AlertPerResult
20-
tactics:
21-
- DefenseEvasion
22-
- Impact
23-
relevantTechniques:
24-
- T1562.001
25-
- T1490
20+
tactics: []
21+
relevantTechniques: []
2622
query: "Veeam_GetSecurityEvents\n| where instanceId == 28100\n| extend RepositoryName\
2723
\ = extract(\"RepositoryName=\\\"(?<RepositoryName>[^\\\"]*)\\\"\", 1, SyslogMessage)\n\
2824
| project\n Date = format_datetime(TimeGenerated, 'dd.MM.yyyy HH:mm'),\n DataSource\
2925
\ = original_host,\n EventId = instanceId,\n [\"User Name\"] = user,\n \
3026
\ [\"Object Name\"] = RepositoryName,\n MessageDetails = Description,\n Severity\
3127
\ = SeverityDescription"
32-
version: 1.0.0
28+
version: 1.0.1
3329
kind: Scheduled
3430
customDetails:
3531
Date: Date

0 commit comments

Comments
 (0)