Skip to content

Commit d304e71

Browse files
JV0812kimsaucejpipkin1
authored
V1 to v2 apps migration (Release_2) + Threat Intel (#4157)
* V1 to V2 apps migration (release_2) * minor fix * Update docs/integrations/security-threat-detection/threat-intel-quick-analysis.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/security-threat-detection/threat-intel-quick-analysis.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/security-threat-detection/threat-intel-quick-analysis.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/security-threat-detection/threat-intel-quick-analysis.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/security-threat-detection/threat-intel-quick-analysis.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/security-threat-detection/threat-intel-quick-analysis.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/security-threat-detection/threat-intel-quick-analysis.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/saas-cloud/microsoft-exchange-trace-logs.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/saas-cloud/gmail-tracelogs.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/saas-cloud/gmail-tracelogs.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/microsoft-azure/teams.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/microsoft-azure/teams.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/microsoft-azure/teams.md * Update docs/integrations/microsoft-azure/teams.md * Fix broken anchor link * Remove FAQ section from Threat Intel Quick Analysis article * Update comments in threat intel quick analysis article * Update docs/integrations/security-threat-detection/threat-intel-quick-analysis.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/security-threat-detection/threat-intel-quick-analysis.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * minor fixes * Update teams.md * Update gmail-tracelogs.md --------- Co-authored-by: Kim (Sumo Logic) <[email protected]> Co-authored-by: John Pipkin <[email protected]>
1 parent 11342a4 commit d304e71

File tree

4 files changed

+259
-39
lines changed

4 files changed

+259
-39
lines changed

docs/integrations/microsoft-azure/teams.md

Lines changed: 28 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -2,14 +2,14 @@
22
id: teams
33
title: Microsoft Teams
44
sidebar_label: Microsoft Teams
5-
description: The Microsoft Teams app provides out-of-the-box dashboards to monitor users, teams, channels and permission changes.
5+
description: The Microsoft Teams app provides out-of-the-box dashboards to monitor users, teams, channels, and permission changes.
66
---
77

88
import useBaseUrl from '@docusaurus/useBaseUrl';
99

1010
<img src={useBaseUrl('img/integrations/microsoft-azure/MSTeams.png')} alt="thumbnail icon" width="75"/>
1111

12-
The Microsoft Teams app provides out-of-the-box dashboards to monitor users, teams, channels and permission changes.
12+
The Microsoft Teams app provides out-of-the-box dashboards to monitor users, teams, channels, and permission changes.
1313

1414

1515
## Log types
@@ -23,7 +23,6 @@ The Teams app provides visibility into the logging that Microsoft exposes in the
2323

2424
For more information, see Microsoft’s [list of Teams Activities](https://docs.microsoft.com/en-us/microsoftteams/audit-log-events#teams-activities).
2525

26-
2726
### Sample log messages
2827

2928
```json
@@ -51,26 +50,29 @@ _sourceCategory="O365/General"
5150

5251
## Collecting logs
5352

54-
This section has instructions for collecting logs for the Sumo App for Teams.
53+
This section has instructions for collecting logs for the Sumo Logic app for Teams.
5554

5655
### Collection process overview
5756

5857
To collect logs for Microsoft Teams, please configure an Office 365 Audit Source. The Teams logs will be present in the “Office 365 General Logs” context. Note, that if you are already collecting logs for Office 365, you can simply make note of the source category configured for the aforementioned context.
5958

59+
## Installing the Microsoft Teams app
60+
61+
This section shows you how to install the Sumo Logic app for Microsoft Teams.
6062

61-
## Installing the Microsoft Teams App
63+
import AppInstall2 from '../../reuse/apps/app-install-v2.md';
6264

63-
This section shows you how to install the Sumo Logic App for Microsoft Teams.
65+
<AppInstall2/>
6466

65-
import AppInstall from '../../reuse/apps/app-install.md';
67+
## Viewing Microsoft Teams dashboards
6668

67-
<AppInstall/>
69+
import ViewDashboards from '../../reuse/apps/view-dashboards.md';
6870

69-
## Viewing Microsoft Teams Dashboards
71+
<ViewDashboards/>
7072

7173
### Overview
7274

73-
The Teams - Overview dashboard provides an at-a-glance view of the state of your Teams environment in terms of user sessions, teams and channel activity, and user role changes
75+
The **Teams - Overview** dashboard provides an at-a-glance view of the state of your Teams environment in terms of user sessions, teams and channel activity, and user role changes.
7476

7577
Use this dashboard to:
7678
* Identify user sessions relative to their locations.
@@ -82,7 +84,7 @@ Use this dashboard to:
8284

8385
### User Sessions
8486

85-
The Teams - User Sessions dashboard provides an in depth view of the user logins and related statistics in your Teams environment
87+
The **Teams - User Sessions** dashboard provides an in depth view of the user logins and related statistics in your Teams environment.
8688

8789
Use this dashboard to:
8890
* Identify user sessions relative to their locations and compare login statistics over time.
@@ -93,7 +95,7 @@ Use this dashboard to:
9395

9496
### Team Statistics
9597

96-
The Teams - Team Statistics dashboard offers complete details on the Team activity occurring in your organization.
98+
The **Teams - Team Statistics** dashboard offers complete details on the Team activity occurring in your organization.
9799

98100
Use this dashboard to:
99101
* Gain insight into teams being added and removed.
@@ -102,10 +104,9 @@ Use this dashboard to:
102104

103105
<img src={useBaseUrl('https://sumologic-app-data.s3.amazonaws.com/dashboards/MicrosoftTeams/Teams+-+Team+Statistics.png')} alt="Team Statistics" />
104106

105-
106107
### Channel Statistics
107108

108-
The Teams - Channel Statistics dashboard offers complete visibility into the Channel activity occurring in your Teams.
109+
The **Teams - Channel Statistics** dashboard offers complete visibility into the Channel activity occurring in your Teams.
109110

110111
Use this dashboard to:
111112
* Gain insight into the channels being added and removed.
@@ -115,13 +116,24 @@ Use this dashboard to:
115116

116117
<img src={useBaseUrl('https://sumologic-app-data.s3.amazonaws.com/dashboards/MicrosoftTeams/Teams+-+Channel+Statistics.png')} alt="Channel Statistics" />
117118

118-
119119
### User and Role Changes
120120

121-
The Teams - User and Role Changes dashboard provides insight on the user and role changes being applied in your environment.
121+
The **Teams - User and Role Changes** dashboard provides insight on the user and role changes being applied in your environment.
122122

123123
Use this dashboard to:
124124
* Report on the users making role changes and the top object types being affected.
125125
* Understand how members are being added, removed, and changed by object name.
126126

127127
<img src={useBaseUrl('https://sumologic-app-data.s3.amazonaws.com/dashboards/MicrosoftTeams/Teams+-+User+and+Role+Changes.png')} alt="User and Role Changes" />
128+
129+
## Upgrading the Microsoft Teams app (optional)
130+
131+
import AppUpdate from '../../reuse/apps/app-update.md';
132+
133+
<AppUpdate/>
134+
135+
## Uninstalling the Microsoft Teams app (optional)
136+
137+
import AppUninstall from '../../reuse/apps/app-uninstall.md';
138+
139+
<AppUninstall/>

docs/integrations/saas-cloud/gmail-tracelogs.md

Lines changed: 19 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -161,22 +161,31 @@ import AppCollectionOPtion2 from '../../reuse/apps/app-collection-option-2.md';
161161

162162
import AppCollectionOPtion3 from '../../reuse/apps/app-collection-option-3.md';
163163

164-
<AppCollectionOPtion3/>
164+
## Viewing the Gmail Trace Logs dashboards
165165

166-
## Viewing Gmail Trace Logs Dashboards
166+
import ViewDashboards from '../../reuse/apps/view-dashboards.md';
167167

168-
**All dashboard have a set of filters** that you can apply to the entire dashboard, as shown in the following example. Click the funnel icon in the top dashboard menu bar to display a scrollable list of filters that are applied across the entire dashboard.
168+
<ViewDashboards/>
169169

170-
You can use filters to drill down and examine the data on a granular level. Filters include client country, client device type, client IP, client request host, client request URI, client request user agent, edge response status, origin IP, and origin response status.
170+
### Security Overview
171171

172-
**Each panel has a set of filters** that are applied to the results for that panel only, as shown in the following example. Click the funnel icon in the top panel menu bar to display a list of panel-specific filters.
173-
174-
### Security Overview Dashboard
175-
176-
**Gmail Trace Logs - Security Overview**. This dashboard lets you monitor spam messages, malware threats, dropped messages, and rejected messages.
172+
The **Gmail Trace Logs - Security Overview** dashboard lets you monitor spam messages, malware threats, dropped messages, and rejected messages.
177173

178174
<img src={useBaseUrl('img/integrations/saas-cloud/tracelogsapp-overview.png')} alt="Gmail Trace Logs Overview" width="900"/>
179175

180-
**CrowdStrike Analysis**. To protect your organisation from threats, the app also scans the SHA256 hash of Gmail attachments with CrowdStrike's threat detection service.
176+
The **CrowdStrike Analysis**. To protect your organisation from threats, the app also scans the SHA256 hash of Gmail attachments with CrowdStrike's threat detection service.
181177

182178
<img src={useBaseUrl('img/integrations/saas-cloud/crowdstrike-analysis.png')} alt="Crowdstrike Analysis" width="900"/>
179+
180+
## Upgrading the Microsoft Teams app (optional)
181+
182+
import AppUpdate from '../../reuse/apps/app-update.md';
183+
184+
<AppUpdate/>
185+
186+
## Uninstalling the Microsoft Teams app (optional)
187+
188+
import AppUninstall from '../../reuse/apps/app-uninstall.md';
189+
190+
<AppUninstall/>
191+

docs/integrations/saas-cloud/microsoft-exchange-trace-logs.md

Lines changed: 18 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -115,17 +115,28 @@ import AppCollectionOPtion3 from '../../reuse/apps/app-collection-option-3.md';
115115

116116
<AppCollectionOPtion3/>
117117

118-
## Viewing Microsoft Exchange Trace Logs Dashboards
118+
## Upgrading the Microsoft Exchange Trace Logs app (optional)
119119

120-
* All dashboard have a set of filters that you can apply to the entire dashboard, as shown in the following example. Click the funnel icon in the top dashboard menu bar to display a scrollable list of filters that are applied across the entire dashboard.
121-
* You can use filters to drill down and examine the data on a granular level. Filters include client country, client device type, client IP, client request host, client request URI, client request user agent, edge response status, origin IP, and origin response status.
122-
* Each panel has a set of filters that are applied to the results for that panel only, as shown in the following example. Click the funnel icon in the top panel menu bar to display a list of panel-specific filters.
120+
import AppUpdate from '../../reuse/apps/app-update.md';
123121

124-
### Overview
122+
<AppUpdate/>
123+
124+
## Uninstalling the Microsoft Exchange Trace Logs app (Optional)
125+
126+
import AppUninstall from '../../reuse/apps/app-uninstall.md';
127+
128+
<AppUninstall/>
125129

126-
**Microsoft Exchange Trace Logs - Overview**. The Dashboard provides information on the delivery status of messages, including outliers, and a summary of the message size. <br/><img src={useBaseUrl('img/integrations/saas-cloud/microsoft-exchange-trace-logs-overview.png')} alt="Microsoft Exchange Trace Logs Overview" width="900"/>
130+
## Viewing Microsoft Exchange Trace Logs dashboards
131+
132+
import ViewDashboards from '../../reuse/apps/view-dashboards.md';
133+
134+
<ViewDashboards/>
135+
136+
### Overview
127137

138+
The **Microsoft Exchange Trace Logs - Overview** dashboard provides information on the delivery status of messages, including outliers, and a summary of the message size. <br/><img src={useBaseUrl('img/integrations/saas-cloud/microsoft-exchange-trace-logs-overview.png')} alt="Microsoft Exchange Trace Logs Overview" width="900"/>
128139

129140
### Message Monitoring
130141

131-
**Microsoft Exchange Trace Logs - Message Monitoring**. The Dashboard mainly focuses on the message traffic, including the number of unique senders and receivers and their domains. It shows the geographical locations of senders, receivers, and failed messages, and performs security threat analysis on the senders. Additionally, it displays the top 10 senders.<br/><img src={useBaseUrl('img/integrations/saas-cloud/microsoft-exchange-trace-logs-message-monitoring.png')} alt="Microsoft Exchange Trace Logs Message Monitoring" width="900"/>
142+
The **Microsoft Exchange Trace Logs - Message Monitoring** dashboard mainly focuses on the message traffic, including the number of unique senders and receivers and their domains. It shows the geographical locations of senders, receivers, and failed messages, and performs security threat analysis on the senders. Additionally, it displays the top 10 senders.<br/><img src={useBaseUrl('img/integrations/saas-cloud/microsoft-exchange-trace-logs-message-monitoring.png')} alt="Microsoft Exchange Trace Logs Message Monitoring" width="900"/>

0 commit comments

Comments
 (0)