Skip to content

Commit d121133

Browse files
committed
asim/rename-to-advanced-security
1 parent 50d84ab commit d121133

28 files changed

+117
-117
lines changed

articles/sentinel/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -336,7 +336,7 @@
336336
href: ../role-based-access-control/built-in-roles.md#all
337337
- name: Microsoft Sentinel roles
338338
href: ../role-based-access-control/built-in-roles.md#security
339-
- name: Advanced SIEM Information Model (ASIM)
339+
- name: Advanced Security Information Model (ASIM)
340340
items:
341341
- name: ASIM content
342342
href: normalization-content.md

articles/sentinel/authentication-normalization-schema.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ For example, Windows sends several authentication events alongside other OS acti
1818

1919
Authentication events include both events from systems that focus on authentication such as VPN gateways or domain controllers, and direct authentication to an end system, such as a computer or firewall.
2020

21-
For more information about normalization in Microsoft Sentinel, see [Normalization and the Advanced SIEM Information Model (ASIM)](normalization.md).
21+
For more information about normalization in Microsoft Sentinel, see [Normalization and the Advanced Security Information Model (ASIM)](normalization.md).
2222

2323
> [!IMPORTANT]
2424
> The Authentication normalization schema is currently in PREVIEW. This feature is provided without a service level agreement, and is not recommended for production workloads.
@@ -179,7 +179,7 @@ An **Actor**, running an *Acting Application* (**ActingApp**) on a *Source Devic
179179
For more information, see:
180180

181181
- Watch the [ASIM Webinar](https://www.youtube.com/watch?v=WoGD-JeC7ng) or review the [slides](https://1drv.ms/b/s!AnEPjr8tHcNmjDY1cro08Fk3KUj-?e=murYHG)
182-
- [Advanced SIEM Information Model (ASIM) overview](normalization.md)
183-
- [Advanced SIEM Information Model (ASIM) schemas](normalization-about-schemas.md)
184-
- [Advanced SIEM Information Model (ASIM) parsers](normalization-parsers-overview.md)
185-
- [Advanced SIEM Information Model (ASIM) content](normalization-content.md)
182+
- [Advanced Security Information Model (ASIM) overview](normalization.md)
183+
- [Advanced Security Information Model (ASIM) schemas](normalization-about-schemas.md)
184+
- [Advanced Security Information Model (ASIM) parsers](normalization-parsers-overview.md)
185+
- [Advanced Security Information Model (ASIM) content](normalization-content.md)

articles/sentinel/ci-cd.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -288,7 +288,7 @@ For more information, see:
288288
289289
- [Discover and deploy Microsoft Sentinel solutions (Public preview)](sentinel-solutions-deploy.md)
290290
- [Microsoft Sentinel data connectors](connect-data-sources.md)
291-
- [Advanced SIEM Information Model (ASIM) parsers (Public preview)](normalization-about-parsers.md)
291+
- [Advanced Security Information Model (ASIM) parsers (Public preview)](normalization-about-parsers.md)
292292
- [Visualize collected data](get-visibility.md)
293293
- [Create custom analytics rules to detect threats](detect-threats-custom.md)
294294
- [Hunt for threats with Microsoft Sentinel](hunting.md)

articles/sentinel/connect-syslog.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -82,11 +82,11 @@ Many device types have their own data connectors appearing in the **Data connect
8282
8383
All connectors listed in the gallery will display any specific instructions on their respective connector pages in the portal, as well as in their sections of the [Microsoft Sentinel data connectors reference](data-connectors-reference.md) page.
8484
85-
If the instructions on your data connector's page in Microsoft Sentinel indicate that the Kusto functions are deployed as [Advanced SIEM Information Model (ASIM)](normalization.md) parsers, make sure that you have the ASIM parsers deployed to your workspace.
85+
If the instructions on your data connector's page in Microsoft Sentinel indicate that the Kusto functions are deployed as [Advanced Security Information Model (ASIM)](normalization.md) parsers, make sure that you have the ASIM parsers deployed to your workspace.
8686

8787
Use the link in the data connector page to deploy your parsers, or follow the instructions from the [Microsoft Sentinel GitHub repository](https://github.com/Azure/Azure-Sentinel/tree/master/ASIM).
8888

89-
For more information, see [Advanced SIEM Information Model (ASIM) parsers](normalization-about-parsers.md).
89+
For more information, see [Advanced Security Information Model (ASIM) parsers](normalization-about-parsers.md).
9090

9191
## Configure the Log Analytics agent
9292

articles/sentinel/create-custom-connector.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -191,7 +191,7 @@ For examples of this method, see:
191191

192192
## Parse your custom connector data
193193

194-
To take advantage of the data collected with your custom connector, [develop Advanced SIM Information Model (SIEM) parsers](normalization-develop-parsers.md) to work with your connector. Using [ASIM](normalization.md) enables Microsoft Sentinel's built-in content to use your custom data and makes it easier for analysts to query the data.
194+
To take advantage of the data collected with your custom connector, [develop Advanced Security Information Model (ASIM) parsers](normalization-develop-parsers.md) to work with your connector. Using [ASIM](normalization.md) enables Microsoft Sentinel's built-in content to use your custom data and makes it easier for analysts to query the data.
195195

196196
If your connector method allows for it, you can implement part of the parsing as part of the connector to improve query time parsing performance:
197197
- **If you've used Logstash**, use the [Grok](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) filter plugin to parse your data.

articles/sentinel/customize-entity-activities.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,7 @@ Here you will write or paste the KQL query that will be used to detect the activ
9090

9191
> [!IMPORTANT]
9292
>
93-
> We recommend that your query uses an [Advanced SIEM Information model (ASIM) parser](normalization-about-parsers.md) and not a built-in table. This ensures that the query will support any current or future relevant data source rather than a single data source.
93+
> We recommend that your query uses an [Advanced Security Information Model (ASIM) parser](normalization-about-parsers.md) and not a built-in table. This ensures that the query will support any current or future relevant data source rather than a single data source.
9494
>
9595
9696
In order to correlate events and detect the custom activity, the KQL requires an input of several parameters, depending on the entity type. The parameters are the various identifiers of the entity in question.

articles/sentinel/data-connectors-reference.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1731,7 +1731,7 @@ For more information, see [Gather insights about your DNS infrastructure with th
17311731
17321732
### Additional instructions for deploying the Windows Forwarded Events connector
17331733
1734-
We recommend installing the [Advanced SIEM Information Model (ASIM)](normalization.md) parsers to ensure full support for data normalization. You can deploy these parsers from the [`Azure-Sentinel` GitHub repository](https://github.com/Azure/Azure-Sentinel/tree/master/Parsers/ASim%20WindowsEvent) using the **Deploy to Azure** button there.
1734+
We recommend installing the [Advanced Security Information Model (ASIM)](normalization.md) parsers to ensure full support for data normalization. You can deploy these parsers from the [`Azure-Sentinel` GitHub repository](https://github.com/Azure/Azure-Sentinel/tree/master/Parsers/ASim%20WindowsEvent) using the **Deploy to Azure** button there.
17351735
17361736
## Windows Firewall
17371737

articles/sentinel/detect-threats-custom.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ In the **Set rule logic** tab, you can either write a query directly in the **Ru
6868
6969
> [!IMPORTANT]
7070
>
71-
> We recommend that your query uses an [Advanced SIEM Information model (ASIM) parser](normalization-about-parsers.md) and not a native table. This will ensure that the query supports any current or future relevant data source rather than a single data source.
71+
> We recommend that your query uses an [Advanced Security Information Model (ASIM) parser](normalization-about-parsers.md) and not a native table. This will ensure that the query supports any current or future relevant data source rather than a single data source.
7272
>
7373
7474

articles/sentinel/dhcp-normalization-schema.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.custom: ignite-fall-2021
1414

1515
The DHCP information model is used to describe events reported by a DHCP server, and is used by Microsoft Sentinel to enable source-agnostic analytics.
1616

17-
For more information, see [Normalization and the Advanced SIEM Information Model (ASIM)](normalization.md).
17+
For more information, see [Normalization and the Advanced Security Information Model (ASIM)](normalization.md).
1818

1919
> [!IMPORTANT]
2020
> The DHCP normalization schema is currently in PREVIEW. This feature is provided without a service level agreement, and is not recommended for production workloads.
@@ -132,7 +132,7 @@ The fields below are specific to DHCP events, but many are similar to fields in
132132
For more information, see:
133133

134134
- Watch the [ASIM Webinar](https://www.youtube.com/watch?v=WoGD-JeC7ng) or review the [slides](https://1drv.ms/b/s!AnEPjr8tHcNmjDY1cro08Fk3KUj-?e=murYHG)
135-
- [Advanced SIEM Information Model (ASIM) overview](normalization.md)
136-
- [Advanced SIEM Information Model (ASIM) schemas](normalization-about-schemas.md)
137-
- [Advanced SIEM Information Model (ASIM) parsers](normalization-parsers-overview.md)
138-
- [Advanced SIEM Information Model (ASIM) content](normalization-content.md)
135+
- [Advanced Security Information Model (ASIM) overview](normalization.md)
136+
- [Advanced Security Information Model (ASIM) schemas](normalization-about-schemas.md)
137+
- [Advanced Security Information Model (ASIM) parsers](normalization-parsers-overview.md)
138+
- [Advanced Security Information Model (ASIM) content](normalization-content.md)

articles/sentinel/dns-normalization-schema.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.custom: ignite-fall-2021
1414

1515
The DNS information model is used to describe events reported by a DNS server or a DNS security system, and is used by Microsoft Sentinel to enable source-agnostic analytics.
1616

17-
For more information, see [Normalization and the Advanced SIEM Information Model (ASIM)](normalization.md).
17+
For more information, see [Normalization and the Advanced Security Information Model (ASIM)](normalization.md).
1818

1919
> [!IMPORTANT]
2020
> The DNS normalization schema is currently in PREVIEW. This feature is provided without a service level agreement, and is not recommended for production workloads.
@@ -324,7 +324,7 @@ You can also provide an extra KQL function called `_imDNS<vendor>Flags_`, which
324324
For more information, see:
325325

326326
- Watch the [ASIM Webinar](https://www.youtube.com/watch?v=WoGD-JeC7ng) or review the [slides](https://1drv.ms/b/s!AnEPjr8tHcNmjDY1cro08Fk3KUj-?e=murYHG)
327-
- [Advanced SIEM Information Model (ASIM) overview](normalization.md)
328-
- [Advanced SIEM Information Model (ASIM) schemas](normalization-about-schemas.md)
329-
- [Advanced SIEM Information Model (ASIM) parsers](normalization-parsers-overview.md)
330-
- [Advanced SIEM Information Model (ASIM) content](normalization-content.md)
327+
- [Advanced Security Information Model (ASIM) overview](normalization.md)
328+
- [Advanced Security Information Model (ASIM) schemas](normalization-about-schemas.md)
329+
- [Advanced Security Information Model (ASIM) parsers](normalization-parsers-overview.md)
330+
- [Advanced Security Information Model (ASIM) content](normalization-content.md)

0 commit comments

Comments
 (0)