Skip to content

Commit 0c51175

Browse files
authored
Merge pull request Azure#13190 from bdudnyk-varonis/feature/varonis-informational-severity
Added support of Informational alerts severity
2 parents e5c460d + cdde345 commit 0c51175

File tree

10 files changed

+26
-9
lines changed

10 files changed

+26
-9
lines changed
Binary file not shown.

Solutions/VaronisSaaS/Data Connectors/VaronisSaaSFunction/Varonis.Sentinel.Functions/Helpers/AlertExtensions.cs

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,8 @@ public static class AlertExtensions
2020
{
2121
["High"] = 0,
2222
["Medium"] = 1,
23-
["Low"] = 2
23+
["Low"] = 2,
24+
["Informational"] = 3
2425
};
2526
}
2627
}

Solutions/VaronisSaaS/Data Connectors/VaronisSaaSFunction/Varonis.Sentinel.Functions/local.settings.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
"LogAnalyticsKey": "",
1010
"LogAnalyticsWorkspace": "",
1111
"AlertRetrievalStart": "2 weeks",
12-
"AlertSeverity": "Low, Medium, High",
12+
"AlertSeverity": "Low, Medium, High, Informational",
1313
"ThreatDetectionPolicies": "",
1414
"AlertStatus": "New, Under Investigation",
1515
"MaxAlertRetrieval": "1000"

Solutions/VaronisSaaS/Data Connectors/VaronisSaaS_API_FunctionApp.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,11 @@
2323
"baseQuery": "VaronisAlerts_CL\n| where Severity_s == \"Low\"",
2424
"legend": "Low severity alerts",
2525
"metricName": "Low severity alerts"
26+
},
27+
{
28+
"baseQuery": "VaronisAlerts_CL\n| where Severity_s == \"Informational\"",
29+
"legend": "Informational severity alerts",
30+
"metricName": "Informational severity alerts"
2631
}
2732
],
2833
"sampleQueries": [

Solutions/VaronisSaaS/Data Connectors/azuredeploy.bicep

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ param threatDetectionPolicies string = ''
3131
param alertStatus string = 'New, Under Investigation'
3232

3333
@description('Specify the alert severity.')
34-
param alertSeverity string = 'Low, Medium, High'
34+
param alertSeverity string = 'Low, Medium, High, Informational'
3535

3636
var functionAppName = 'VaronisSaaS-${uniqueString(resourceGroup().id)}'
3737
var functionWorkerRuntime = 'dotnet'

Solutions/VaronisSaaS/Data Connectors/azuredeploy.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,7 @@
7171
},
7272
"alertSeverity": {
7373
"type": "string",
74-
"defaultValue": "Low, Medium, High",
74+
"defaultValue": "Low, Medium, High, Informational",
7575
"metadata": {
7676
"description": "Specify the alert severity."
7777
}

Solutions/VaronisSaaS/Data/Solution_VaronisSaaS.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
"Workbooks": ["Workbooks/VaronisSaaS.json"],
77
"Data Connectors": ["Data Connectors/VaronisSaaS_API_FunctionApp.json"],
88
"BasePath": "C:\\Projects\\DataIntegration\\Azure-Sentinel\\Solutions\\VaronisSaaS",
9-
"Version": "3.0.2",
9+
"Version": "3.0.3",
1010
"Metadata": "SolutionMetadata.json",
1111
"TemplateSpec": true,
1212
"Is1PConnector": false
8.58 KB
Binary file not shown.

Solutions/VaronisSaaS/Package/mainTemplate.json

Lines changed: 14 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@
3939
},
4040
"variables": {
4141
"_solutionName": "VaronisSaaS",
42-
"_solutionVersion": "3.0.2",
42+
"_solutionVersion": "3.0.3",
4343
"solutionId": "varonis.microsoft-sentinel-solution-varonissaas",
4444
"_solutionId": "[variables('solutionId')]",
4545
"workbookVersion1": "1.0.0",
@@ -70,7 +70,7 @@
7070
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
7171
],
7272
"properties": {
73-
"description": "VaronisSaaS Workbook with template version 3.0.2",
73+
"description": "VaronisSaaS Workbook with template version 3.0.3",
7474
"mainTemplate": {
7575
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
7676
"contentVersion": "[variables('workbookVersion1')]",
@@ -157,7 +157,7 @@
157157
"[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]"
158158
],
159159
"properties": {
160-
"description": "VaronisSaaS data connector with template version 3.0.2",
160+
"description": "VaronisSaaS data connector with template version 3.0.3",
161161
"mainTemplate": {
162162
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
163163
"contentVersion": "[variables('dataConnectorVersion1')]",
@@ -196,6 +196,11 @@
196196
"baseQuery": "VaronisAlerts_CL\n| where Severity_s == \"Low\"",
197197
"legend": "Low severity alerts",
198198
"metricName": "Low severity alerts"
199+
},
200+
{
201+
"baseQuery": "VaronisAlerts_CL\n| where Severity_s == \"Informational\"",
202+
"legend": "Informational severity alerts",
203+
"metricName": "Informational severity alerts"
199204
}
200205
],
201206
"sampleQueries": [
@@ -387,6 +392,11 @@
387392
"baseQuery": "VaronisAlerts_CL\n| where Severity_s == \"Low\"",
388393
"legend": "Low severity alerts",
389394
"metricName": "Low severity alerts"
395+
},
396+
{
397+
"baseQuery": "VaronisAlerts_CL\n| where Severity_s == \"Informational\"",
398+
"legend": "Informational severity alerts",
399+
"metricName": "Informational severity alerts"
390400
}
391401
],
392402
"dataTypes": [
@@ -484,7 +494,7 @@
484494
"apiVersion": "2023-04-01-preview",
485495
"location": "[parameters('workspace-location')]",
486496
"properties": {
487-
"version": "3.0.2",
497+
"version": "3.0.3",
488498
"kind": "Solution",
489499
"contentSchemaVersion": "3.0.0",
490500
"displayName": "VaronisSaaS",
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
22
|-------------|--------------------------------|---------------------------------------------|
3+
| 3.0.3 | 25-11-2025 | Add Informational severity level support |
34
| 3.0.2 | 12-09-2025 | Save last alert ingest time |
45
| 3.0.1 | 02-12-2025 | Bug fixes |
56
| 3.0.0 | 02-07-2024 | Refactor azure function |

0 commit comments

Comments
 (0)