Skip to content

Commit daeb278

Browse files
author
Jill Grant
authored
Merge pull request #288949 from Saisang/dataconnectorsautogen-1022
[AUTOGEN] Data connectors monthly update
2 parents 5c7370e + 6f285bb commit daeb278

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

42 files changed

+1966
-64
lines changed

articles/sentinel/TOC.yml

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -286,6 +286,8 @@
286286
href: data-connectors/armis-activities.md
287287
- name: Armis Alerts (using Azure Functions)
288288
href: data-connectors/armis-alerts.md
289+
- name: Armis Alerts Activities (using Azure Functions)
290+
href: data-connectors/armis-alerts-activities.md
289291
- name: Armis Devices (using Azure Functions)
290292
href: data-connectors/armis-devices.md
291293
- name: Armorblox (using Azure Functions)
@@ -304,6 +306,8 @@
304306
href: data-connectors/azure-activity.md
305307
- name: Azure Batch Account
306308
href: data-connectors/azure-batch-account.md
309+
- name: Azure CloudNGFW By Palo Alto Networks
310+
href: data-connectors/azure-cloudngfw-by-palo-alto-networks.md
307311
- name: Azure Cognitive Search
308312
href: data-connectors/azure-cognitive-search.md
309313
- name: Azure DDoS Protection
@@ -362,6 +366,8 @@
362366
href: data-connectors/corelight-connector-exporter.md
363367
- name: Cortex XDR - Incidents
364368
href: data-connectors/cortex-xdr-incidents.md
369+
- name: Cribl
370+
href: data-connectors/cribl.md
365371
- name: CrowdStrike Falcon Adversary Intelligence (using Azure Functions)
366372
href: data-connectors/crowdstrike-falcon-adversary-intelligence.md
367373
- name: Crowdstrike Falcon Data Replicator (using Azure Functions)
@@ -440,10 +446,22 @@
440446
href: data-connectors/greynoise-threat-intelligence.md
441447
- name: HackerView Intergration (using Azure Functions)
442448
href: data-connectors/hackerview-intergration.md
449+
- name: HYAS Protect (using Azure Functions)
450+
href: data-connectors/hyas-protect.md
443451
- name: Holm Security Asset Data (using Azure Functions)
444452
href: data-connectors/holm-security-asset-data.md
453+
- name: Illumio SaaS (using Azure Functions)
454+
href: data-connectors/illumio-saas.md
445455
- name: Imperva Cloud WAF (using Azure Functions)
446456
href: data-connectors/imperva-cloud-waf.md
457+
- name: Infoblox Data Connector via REST API (using Azure Functions)
458+
href: data-connectors/infoblox-data-connector-via-rest-api.md
459+
- name: Infoblox Cloud Data Connector via AMA
460+
href: data-connectors/recommended-infoblox-cloud-data-connector-via-ama.md
461+
- name: Infoblox SOC Insight Data Connector via AMA
462+
href: data-connectors/recommended-infoblox-soc-insight-data-connector-via-ama.md
463+
- name: Infoblox SOC Insight Data Connector via REST API
464+
href: data-connectors/infoblox-soc-insight-data-connector-via-rest-api.md
447465
- name: InfoSecGlobal Data Connector
448466
href: data-connectors/infosecglobal-data-connector.md
449467
- name: IONIX Security Logs
@@ -546,8 +564,12 @@
546564
href: data-connectors/palo-alto-prisma-cloud-cspm.md
547565
- name: Perimeter 81 Activity Logs
548566
href: data-connectors/perimeter-81-activity-logs.md
567+
- name: Phosphorus Devices
568+
href: data-connectors/phosphorus-devices.md
549569
- name: Prancer Data Connector
550570
href: data-connectors/prancer-data-connector.md
571+
- name: Premium Microsoft Defender Threat Intelligence (Preview)
572+
href: data-connectors/premium-microsoft-defender-threat-intelligence.md
551573
- name: Proofpoint On Demand Email Security (using Azure Functions)
552574
href: data-connectors/proofpoint-on-demand-email-security.md
553575
- name: Proofpoint TAP (using Azure Functions)
@@ -556,6 +578,8 @@
556578
href: data-connectors/qualys-vm-knowledgebase.md
557579
- name: Qualys Vulnerability Management (using Azure Functions)
558580
href: data-connectors/qualys-vulnerability-management.md
581+
- name: Radiflow iSID via AMA
582+
href: data-connectors/radiflow-isid-via-ama.md
559583
- name: Rapid7 Insight Platform Vulnerability Management Reports (using Azure Functions)
560584
href: data-connectors/rapid7-insight-platform-vulnerability-management-reports.md
561585
- name: Rubrik Security Cloud data connector (using Azure Functions)
@@ -572,6 +596,8 @@
572596
href: data-connectors/sentinelone.md
573597
- name: Seraphic Web Security
574598
href: data-connectors/seraphic-web-security.md
599+
- name: Silverfort Admin Console
600+
href: data-connectors/silverfort-admin-console.md
575601
- name: Slack Audit (using Azure Functions)
576602
href: data-connectors/slack-audit.md
577603
- name: Snowflake (using Azure Functions)
@@ -634,6 +660,10 @@
634660
href: data-connectors/zero-networks-segment-audit.md
635661
- name: Zero Networks Segment Audit (Function) (using Azure Functions)
636662
href: data-connectors/zero-networks-segment-audit.md
663+
- name: ZeroFox CTI (using Azure Functions)
664+
href: data-connectors/zerofox-cti.md
665+
- name: ZeroFox Enterprise - Alerts (Polling CCP)
666+
href: data-connectors/zerofox-enterprise-alerts-polling-ccp.md
637667
- name: Zimperium Mobile Threat Defense
638668
href: data-connectors/zimperium-mobile-threat-defense.md
639669
- name: Zoom Reports (using Azure Functions)

articles/sentinel/data-connectors-reference.md

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -104,6 +104,7 @@ For more information about the codeless connector platform, see [Create a codele
104104

105105
- [Armis Activities (using Azure Functions)](data-connectors/armis-activities.md)
106106
- [Armis Alerts (using Azure Functions)](data-connectors/armis-alerts.md)
107+
- [Armis Alerts Activities (using Azure Functions)](data-connectors/armis-alerts-activities.md)
107108
- [Armis Devices (using Azure Functions)](data-connectors/armis-devices.md)
108109

109110
## Armorblox
@@ -175,6 +176,10 @@ For more information about the codeless connector platform, see [Create a codele
175176

176177
- [Corelight Connector Exporter](data-connectors/corelight-connector-exporter.md)
177178

179+
## Cribl
180+
181+
- [Cribl](data-connectors/cribl.md)
182+
178183
## Crowdstrike
179184

180185
- [CrowdStrike Falcon Adversary Intelligence (using Azure Functions)](data-connectors/crowdstrike-falcon-adversary-intelligence.md)
@@ -278,6 +283,14 @@ For more information about the codeless connector platform, see [Create a codele
278283

279284
- [GreyNoise Threat Intelligence (using Azure Functions)](data-connectors/greynoise-threat-intelligence.md)
280285

286+
## HYAS Infosec Inc
287+
288+
- [HYAS Protect (using Azure Functions)](data-connectors/hyas-protect.md)
289+
290+
## Illumio, Inc.
291+
292+
- [Illumio SaaS (using Azure Functions)](data-connectors/illumio-saas.md)
293+
281294
## H.O.L.M. Security Sweden AB
282295

283296
- [Holm Security Asset Data (using Azure Functions)](data-connectors/holm-security-asset-data.md)
@@ -286,6 +299,13 @@ For more information about the codeless connector platform, see [Create a codele
286299

287300
- [Imperva Cloud WAF (using Azure Functions)](data-connectors/imperva-cloud-waf.md)
288301

302+
## Infoblox
303+
304+
- [[Recommended] Infoblox Cloud Data Connector via AMA](data-connectors/recommended-infoblox-cloud-data-connector-via-ama.md)
305+
- [[Recommended] Infoblox SOC Insight Data Connector via AMA](data-connectors/recommended-infoblox-soc-insight-data-connector-via-ama.md)
306+
- [Infoblox Data Connector via REST API (using Azure Functions)](data-connectors/infoblox-data-connector-via-rest-api.md)
307+
- [Infoblox SOC Insight Data Connector via REST API](data-connectors/infoblox-soc-insight-data-connector-via-rest-api.md)
308+
289309
## Infosec Global
290310

291311
- [InfoSecGlobal Data Connector](data-connectors/infosecglobal-data-connector.md)
@@ -348,6 +368,7 @@ For more information about the codeless connector platform, see [Create a codele
348368
- [Azure Stream Analytics](data-connectors/azure-stream-analytics.md)
349369
- [Syslog via AMA](data-connectors/syslog-via-ama.md)
350370
- [Microsoft Defender Threat Intelligence (Preview)](data-connectors/microsoft-defender-threat-intelligence.md)
371+
- [Premium Microsoft Defender Threat Intelligence (Preview)](data-connectors/premium-microsoft-defender-threat-intelligence.md)
351372
- [Threat intelligence - TAXII](data-connectors/threat-intelligence-taxii.md)
352373
- [Threat Intelligence Platforms](data-connectors/threat-intelligence-platforms.md)
353374
- [Threat Intelligence Upload Indicators API (Preview)](data-connectors/threat-intelligence-upload-indicators-api.md)
@@ -423,11 +444,16 @@ For more information about the codeless connector platform, see [Create a codele
423444
## Palo Alto Networks
424445

425446
- [Palo Alto Prisma Cloud CSPM (using Azure Functions)](data-connectors/palo-alto-prisma-cloud-cspm.md)
447+
- [Azure CloudNGFW By Palo Alto Networks](data-connectors/azure-cloudngfw-by-palo-alto-networks.md)
426448

427449
## Perimeter 81
428450

429451
- [Perimeter 81 Activity Logs](data-connectors/perimeter-81-activity-logs.md)
430452

453+
## Phosphorus Cybersecurity
454+
455+
- [Phosphorus Devices](data-connectors/phosphorus-devices.md)
456+
431457
## Prancer Enterprise
432458

433459
- [Prancer Data Connector](data-connectors/prancer-data-connector.md)
@@ -442,6 +468,10 @@ For more information about the codeless connector platform, see [Create a codele
442468
- [Qualys Vulnerability Management (using Azure Functions)](data-connectors/qualys-vulnerability-management.md)
443469
- [Qualys VM KnowledgeBase (using Azure Functions)](data-connectors/qualys-vm-knowledgebase.md)
444470

471+
## Radiflow
472+
473+
- [Radiflow iSID via AMA](data-connectors/radiflow-isid-via-ama.md)
474+
445475
## Rubrik, Inc.
446476

447477
- [Rubrik Security Cloud data connector (using Azure Functions)](data-connectors/rubrik-security-cloud-data-connector.md)
@@ -470,6 +500,10 @@ For more information about the codeless connector platform, see [Create a codele
470500

471501
- [Seraphic Web Security](data-connectors/seraphic-web-security.md)
472502

503+
## Silverfort Ltd.
504+
505+
- [Silverfort Admin Console](data-connectors/silverfort-admin-console.md)
506+
473507
## Slack
474508

475509
- [Slack Audit (using Azure Functions)](data-connectors/slack-audit.md)
@@ -545,6 +579,11 @@ For more information about the codeless connector platform, see [Create a codele
545579
- [Zero Networks Segment Audit](data-connectors/zero-networks-segment-audit.md)
546580
- [Zero Networks Segment Audit (Function) (using Azure Functions)](data-connectors/zero-networks-segment-audit.md)
547581

582+
## Zerofox, Inc.
583+
584+
- [ZeroFox CTI (using Azure Functions)](data-connectors/zerofox-cti.md)
585+
- [ZeroFox Enterprise - Alerts (Polling CCP)](data-connectors/zerofox-enterprise-alerts-polling-ccp.md)
586+
548587
## Zimperium, Inc.
549588

550589
- [Zimperium Mobile Threat Defense](data-connectors/zimperium-mobile-threat-defense.md)

articles/sentinel/data-connectors/abnormalsecurity.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: "AbnormalSecurity (using Azure Functions) connector for Microsoft Sentine
33
description: "Learn how to install the connector AbnormalSecurity (using Azure Functions) to connect your data source to Microsoft Sentinel."
44
author: cwatson-cat
55
ms.topic: how-to
6-
ms.date: 04/26/2024
6+
ms.date: 10/15/2024
77
ms.service: microsoft-sentinel
88
ms.author: cwatson
99
ms.collection: sentinel-data-connector
@@ -109,7 +109,7 @@ If you're already signed in, go to the next step.
109109

110110
d. **Enter a globally unique name for the function app:** Type a name that is valid in a URL path. The name you type is validated to make sure that it's unique in Azure Functions. (e.g. AbnormalSecurityXX).
111111

112-
e. **Select a runtime:** Choose Python 3.8.
112+
e. **Select a runtime:** Choose Python 3.11.
113113

114114
f. Select a location for new resources. For better performance and lower costs choose the same [region](https://azure.microsoft.com/regions/) where Microsoft Sentinel is located.
115115

articles/sentinel/data-connectors/alicloud.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: "AliCloud (using Azure Functions) connector for Microsoft Sentinel"
33
description: "Learn how to install the connector AliCloud (using Azure Functions) to connect your data source to Microsoft Sentinel."
44
author: cwatson-cat
55
ms.topic: how-to
6-
ms.date: 04/26/2024
6+
ms.date: 10/15/2024
77
ms.service: microsoft-sentinel
88
ms.author: cwatson
99
ms.collection: sentinel-data-connector
@@ -113,7 +113,7 @@ If you're already signed in, go to the next step.
113113

114114
d. **Enter a globally unique name for the function app:** Type a name that is valid in a URL path. The name you type is validated to make sure that it's unique in Azure Functions. (e.g. AliCloudXXXXX).
115115

116-
e. **Select a runtime:** Choose Python 3.8.
116+
e. **Select a runtime:** Choose Python 3.11.
117117

118118
f. Select a location for new resources. For better performance and lower costs choose the same [region](https://azure.microsoft.com/regions/) where Microsoft Sentinel is located.
119119

articles/sentinel/data-connectors/api-protection.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: "API Protection connector for Microsoft Sentinel"
33
description: "Learn how to install the connector API Protection to connect your data source to Microsoft Sentinel."
44
author: cwatson-cat
55
ms.topic: how-to
6-
ms.date: 04/26/2024
6+
ms.date: 10/15/2024
77
ms.service: microsoft-sentinel
88
ms.author: cwatson
99
ms.collection: sentinel-data-connector
@@ -65,7 +65,7 @@ The installation process is documented in great detail in the GitHub repository
6565

6666
Step 2: Retrieve the workspace access credentials
6767

68-
The first installation step is to retrieve both your **Workspace ID** and **Primary Key** from the Sentinel platform.
68+
The first installation step is to retrieve both your **Workspace ID** and **Primary Key** from the Microsoft Sentinel platform.
6969
Copy the values shown below and save them for configuration of the API log forwarder integration.
7070

7171

@@ -89,15 +89,15 @@ In order to test the data ingestion the user should deploy the sample *httpbin*
8989

9090
4.1 Install the sample
9191

92-
The sample application can be installed locally using a [Docker compose file](https://github.com/42Crunch/azure-sentinel-integration/blob/main/sample-deployment/docker-compose.yml) which will install the httpbin API server, the 42Crunch API protection and the Sentinel log forwarder. Set the environment variables as required using the values copied from step 2.
92+
The sample application can be installed locally using a [Docker compose file](https://github.com/42Crunch/azure-sentinel-integration/blob/main/sample-deployment/docker-compose.yml) which will install the httpbin API server, the 42Crunch API protection and the Microsoft Sentinel log forwarder. Set the environment variables as required using the values copied from step 2.
9393

9494
4.2 Run the sample
9595

9696
Verfify the API protection is connected to the 42Crunch platform, and then exercise the API locally on the *localhost* at port 8080 using Postman, curl, or similar. You should see a mixture of passing and failing API calls.
9797

9898
4.3 Verify the data ingestion on Log Analytics
9999

100-
After approximately 20 minutes access the Log Analytics workspace on your Sentinel installation, and locate the *Custom Logs* section verify that a *apifirewall_log_1_CL* table exists. Use the sample queries to examine the data.
100+
After approximately 20 minutes access the Log Analytics workspace on your Microsoft Sentinel installation, and locate the *Custom Logs* section verify that a *apifirewall_log_1_CL* table exists. Use the sample queries to examine the data.
101101

102102

103103

0 commit comments

Comments
 (0)