|
34 | 34 | "_email": "[variables('email')]", |
35 | 35 | "_solutionName": "Acronis Cyber Protect Cloud", |
36 | 36 | "_solutionVersion": "3.0.0", |
37 | | - "solutionId": "91996410.azure-sentinel-solution-acronis-cyber-protect", |
| 37 | + "solutionId": "acronisinternationalgmbh.azure-sentinel-solution-acronis-cyber-protect", |
38 | 38 | "_solutionId": "[variables('solutionId')]", |
39 | 39 | "analyticRuleObject1": { |
40 | 40 | "analyticRuleVersion1": "1.0.0", |
|
177 | 177 | { |
178 | 178 | "fieldMappings": [ |
179 | 179 | { |
180 | | - "identifier": "Address", |
181 | | - "columnName": "initiator_ip" |
| 180 | + "columnName": "initiator_ip", |
| 181 | + "identifier": "Address" |
182 | 182 | } |
183 | 183 | ], |
184 | 184 | "entityType": "IP" |
|
192 | 192 | "alertDisplayNameFormat": "Acronis - Login from Abnormal IP ({{initiator_ip}}) - Low Occurrence ({{LoginCount}})" |
193 | 193 | }, |
194 | 194 | "incidentConfiguration": { |
195 | | - "createIncident": true, |
196 | 195 | "groupingConfiguration": { |
197 | | - "matchingMethod": "Selected", |
198 | | - "enabled": true, |
199 | | - "reopenClosedIncident": true, |
200 | | - "lookbackDuration": "P7D", |
201 | 196 | "groupByEntities": [ |
202 | 197 | "IP" |
203 | | - ] |
204 | | - } |
| 198 | + ], |
| 199 | + "reopenClosedIncident": true, |
| 200 | + "enabled": true, |
| 201 | + "matchingMethod": "Selected", |
| 202 | + "lookbackDuration": "P7D" |
| 203 | + }, |
| 204 | + "createIncident": true |
205 | 205 | } |
206 | 206 | } |
207 | 207 | }, |
|
295 | 295 | { |
296 | 296 | "fieldMappings": [ |
297 | 297 | { |
298 | | - "identifier": "HostName", |
299 | | - "columnName": "DeviceName" |
| 298 | + "columnName": "DeviceName", |
| 299 | + "identifier": "HostName" |
300 | 300 | } |
301 | 301 | ], |
302 | 302 | "entityType": "Host" |
|
309 | 309 | "DeviceName": "DeviceName" |
310 | 310 | }, |
311 | 311 | "incidentConfiguration": { |
312 | | - "createIncident": true, |
313 | 312 | "groupingConfiguration": { |
314 | | - "matchingMethod": "AnyAlert", |
315 | | - "enabled": true, |
316 | 313 | "reopenClosedIncident": true, |
| 314 | + "enabled": true, |
| 315 | + "matchingMethod": "AnyAlert", |
317 | 316 | "lookbackDuration": "P1D" |
318 | | - } |
| 317 | + }, |
| 318 | + "createIncident": true |
319 | 319 | } |
320 | 320 | } |
321 | 321 | }, |
|
406 | 406 | { |
407 | 407 | "fieldMappings": [ |
408 | 408 | { |
409 | | - "identifier": "HostName", |
410 | | - "columnName": "DeviceName" |
| 409 | + "columnName": "DeviceName", |
| 410 | + "identifier": "HostName" |
411 | 411 | } |
412 | 412 | ], |
413 | 413 | "entityType": "Host" |
|
420 | 420 | "DeviceName": "DeviceName" |
421 | 421 | }, |
422 | 422 | "incidentConfiguration": { |
423 | | - "createIncident": true, |
424 | 423 | "groupingConfiguration": { |
425 | | - "matchingMethod": "AnyAlert", |
426 | | - "enabled": true, |
427 | 424 | "reopenClosedIncident": true, |
| 425 | + "enabled": true, |
| 426 | + "matchingMethod": "AnyAlert", |
428 | 427 | "lookbackDuration": "P1D" |
429 | | - } |
| 428 | + }, |
| 429 | + "createIncident": true |
430 | 430 | } |
431 | 431 | } |
432 | 432 | }, |
|
522 | 522 | { |
523 | 523 | "fieldMappings": [ |
524 | 524 | { |
525 | | - "identifier": "HostName", |
526 | | - "columnName": "DeviceName" |
| 525 | + "columnName": "DeviceName", |
| 526 | + "identifier": "HostName" |
527 | 527 | } |
528 | 528 | ], |
529 | 529 | "entityType": "Host" |
|
536 | 536 | "DeviceName": "DeviceName" |
537 | 537 | }, |
538 | 538 | "incidentConfiguration": { |
539 | | - "createIncident": true, |
540 | 539 | "groupingConfiguration": { |
541 | | - "matchingMethod": "AnyAlert", |
542 | | - "enabled": true, |
543 | 540 | "reopenClosedIncident": true, |
| 541 | + "enabled": true, |
| 542 | + "matchingMethod": "AnyAlert", |
544 | 543 | "lookbackDuration": "P1D" |
545 | | - } |
| 544 | + }, |
| 545 | + "createIncident": true |
546 | 546 | } |
547 | 547 | } |
548 | 548 | }, |
|
1639 | 1639 | "contentSchemaVersion": "3.0.0", |
1640 | 1640 | "displayName": "Acronis Cyber Protect Cloud", |
1641 | 1641 | "publisherDisplayName": "Acronis International GmbH", |
1642 | | - "descriptionHtml": "<p><strong>Note:</strong> Please refer to the following before installing the solution:</p>\n<p>• Review the solution <a href=\"https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Acronis%20Cyber%20Protect%20Cloud/ReleaseNotes.md\">Release Notes</a></p>\n<p>• There may be <a href=\"https://aka.ms/sentinelsolutionsknownissues\">known issues</a> pertaining to this Solution, please refer to them before installing.</p>\n<p>The Acronis Cyber Protect Cloud solution for Microsoft Sentinel enables companies to ingest Acronis alerts, events, and activities into Microsoft Sentinel. The data is initially stored on a device on the company network (<a href=\"https://www.acronis.com/en-us/support/documentation/CyberProtectionService/index.html#siem-plans.html\">https://www.acronis.com/en-us/support/documentation/CyberProtectionService/index.html#siem-plans.html</a>) using the Acronis agent as a writer. The integration includes custom Acronis detection rules and hunting queries to help companies proactively hunt for threats.</p>\n<p><strong>Analytic Rules:</strong> 4, <strong>Hunting Queries:</strong> 13</p>\n<p><a href=\"https://aka.ms/azuresentinel\">Learn more about Microsoft Sentinel</a> | <a href=\"https://aka.ms/azuresentinelsolutionsdoc\">Learn more about Solutions</a></p>\n", |
| 1642 | + "descriptionHtml": "<p><strong>Note:</strong> Please refer to the following before installing the solution:</p>\n<p>• Review the solution <a href=\"https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Acronis%20Cyber%20Protect%20Cloud/ReleaseNotes.md\">Release Notes</a></p>\n<p>• There may be <a href=\"https://aka.ms/sentinelsolutionsknownissues\">known issues</a> pertaining to this Solution, please refer to them before installing.</p>\n<p>The Acronis Cyber Protect Cloud solution for Microsoft Sentinel enables companies to ingest Acronis alerts, events, and activities into Microsoft Sentinel. The data is initially stored on a device on the company network using the Acronis agent as a writer. <a href=\"https://www.acronis.com/en-us/support/documentation/CyberProtectionService/index.html#siem-plans.html\">See Acronis SIEM Connector documentation here</a> The integration includes custom Acronis detection rules and hunting queries to help companies proactively hunt for threats.</p>\n<p><strong>Analytic Rules:</strong> 4, <strong>Hunting Queries:</strong> 13</p>\n<p><a href=\"https://aka.ms/azuresentinel\">Learn more about Microsoft Sentinel</a> | <a href=\"https://aka.ms/azuresentinelsolutionsdoc\">Learn more about Solutions</a></p>\n", |
1643 | 1643 | "contentKind": "Solution", |
1644 | 1644 | "contentProductId": "[variables('_solutioncontentProductId')]", |
1645 | 1645 | "id": "[variables('_solutioncontentProductId')]", |
|
0 commit comments