You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/cse/rules/cse-rules-syntax.md
+1-6Lines changed: 1 addition & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -645,16 +645,11 @@ When an entity is processed by a rule using the `hasThreatMatch` function and is
645
645
Parameters:
646
646
***`<fields>`**. A list of comma-separated [field names](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/schema/full_schema.md). At least one field name is required.
647
647
***`<filters>`**. A logical expression using [indicator attributes](/docs/security/threat-intelligence/upload-formats/#normalized-json-format). Allowed in the filtering are parentheses `()`; `OR` and `AND` boolean operators; and comparison operators `=`, `<`, `>`, `=<`, `>=`, `!=`. <br/>You can filter on the following indicator attributes:
648
-
*`actors`. An identified threat actor such as an individual, organization, or group.
649
648
*`confidence` Confidence that the data represents a valid threat, where 100 is highest. Malicious confidence scores from different sources are normalized and mapped to a 0-100 numerical value.
650
-
*`id`. ID of the indicator.
651
649
*`indicator`. Value of the indicator, such as an IP address, file name, email address, etc.
652
-
*`killChain`. The various phases an attacker may undertake to achieve their objectives (for example, `reconnaissance`, `weaponization`, `delivery`, `exploitation`, `installation`, `command-and-control`, `actions-on-objectives`).
653
650
*`source`. The source in the Sumo Logic datastore displayed in the **Threat Intelligence** tab.
654
-
*`threatType`. The threat type of the indicator (for example, `anomalous-activity`, `anonymization`, `benign`, `compromised`, `malicious-activity`, `attribution`, `unknown`).
651
+
*`threat_type`. The threat type of the indicator (for example, `anomalous-activity`, `anonymization`, `benign`, `compromised`, `malicious-activity`, `attribution`, `unknown`).
655
652
*`type`. The indicator type (for example, `ipv4-addr`, `domain-name`, `'file:hashes`, etc.)
656
-
*`validFrom`. Beginning time this indicator is valid.
657
-
*`validUntil`. Ending time this indicator is valid.
658
653
***`<indicators>`**. An optional case insensitive option that describes how indicators should be matched with regard to their validity. Accepted values are:
659
654
*`active_indicators`. Match active indicators only (default).
660
655
*`expired_indicators`. Match expired indicators only.
This is a logs-only app. For collecting metrics and enabling comprehensive monitoring on both Linux and Windows, use the [Microsoft SQL Server - OpenTelemetry App](/docs/integrations/microsoft-azure/opentelemetry/sql-server-opentelemetry).
16
+
:::
17
+
14
18
The Sumo Logic app for Microsoft SQL Server is a logs-based app that provides insight into your SQL Server for Linux. The app consists of predefined dashboards, providing visibility into your environment for real-time or historical analysis on backup, restore mirroring, general health and operations of your system.
15
19
16
20
This app has been tested with following SQL Server versions:
@@ -142,7 +146,7 @@ Following is the query from **Error and warning count** panel from the **SQL Ser
142
146
143
147
### Overview
144
148
145
-
The **SQL Server - Overview** dashboard provides a snapshot overview of your SQL Server instance. Use this dashboard to understand CPU, memory, and disk utilization of your SQL Server(s) deployed in your cluster. This dashboard also provides login activities and methods by users.
149
+
The **SQL Server Linux - Overview** dashboard provides a snapshot overview of your SQL Server instance. Use this dashboard to understand CPU, memory, and disk utilization of your SQL Server(s) deployed in your cluster. This dashboard also provides login activities and methods by users.
146
150
147
151
Use this dashboard to:
148
152
- Keep track of deadlocks, errors, backup failures, mirroring errors, and insufficient space issue counts.
@@ -152,7 +156,7 @@ Use this dashboard to:
152
156
153
157
### General Health
154
158
155
-
The **SQL Server - General Health** dashboard provides you the overall health of SQL Server. Use this dashboard to analyze server events including stopped/up servers and its corresponding down/uptime, monitor disk space percentage utilization, wait time trend, and app-domain issues by SQL server.
159
+
The **SQL Server Linux - General Health** dashboard provides you the overall health of SQL Server. Use this dashboard to analyze server events including stopped/up servers and its corresponding down/uptime, monitor disk space percentage utilization, wait time trend, and app-domain issues by SQL server.
156
160
157
161
Use this dashboard to:
158
162
@@ -164,7 +168,7 @@ Use this dashboard to:
164
168
165
169
### Backup Restore Mirroring
166
170
167
-
The **SQL Server - Backup Restore Mirroring** dashboard provides information about:
171
+
The **SQL Server Linux - Backup Restore Mirroring** dashboard provides information about:
168
172
169
173
- Transaction log backup events
170
174
- Database backup events
@@ -176,7 +180,7 @@ The **SQL Server - Backup Restore Mirroring** dashboard provides information abo
176
180
177
181
### Operations
178
182
179
-
The **SQL Server - Operations** dashboard displays recent server configuration changes, number and type of configuration updates, error and warnings, high severity error, and warning trends.
183
+
The **SQL Server Linux - Operations** dashboard displays recent server configuration changes, number and type of configuration updates, error and warnings, high severity error, and warning trends.
180
184
181
185
Use this dashboard to:
182
186
@@ -195,10 +199,10 @@ import CreateMonitors from '../../../reuse/apps/create-monitors.md';
|`SQL Server - AppDomain`| This alert is triggered when AppDomain-related issues are detected in your SQL Server instance. | Count `>=` 1 | Count `<` 1 |
199
-
|`SQL Server - Backup Fail`| This alert is triggered when the SQL Server backup fails. | Count `>=` 1 | Count `<` 1 |
200
-
|`SQL Server - Deadlock`| This alert is triggered when deadlocks are detected in a SQL Server instance. | Count `>` 5 | Count `<=` 5 |
201
-
|`SQL Server - Instance Down`| This alert is triggered when the SQL Server instance is down for 5 minutes. | Count `>` 0 | Count `<=` 0 |
202
-
|`SQL Server - Insufficient Space`| This alert is triggered when the SQL Server instance cannot allocate a new page for the database due to insufficient disk space in the filegroup. | Count `>` 0 | Count `<=` 0 |
203
-
|`SQL Server - Login Fail`| This alert is triggered when the user is unable to login to the SQL Server. | Count `>=` 1 | Count `<` 1 |
204
-
|`SQL Server - Mirroring Error`| This alert is triggered when an error occurs in SQL Server mirroring. | Count `>=` 1 | Count `<` 1 |
202
+
|`SQL Server Linux - AppDomain`| This alert is triggered when AppDomain-related issues are detected in your SQL Server instance. | Count `>=` 1 | Count `<` 1 |
203
+
|`SQL Server Linux - Backup Fail`| This alert is triggered when the SQL Server backup fails. | Count `>=` 1 | Count `<` 1 |
204
+
|`SQL Server Linux - Deadlock`| This alert is triggered when deadlocks are detected in a SQL Server instance. | Count `>` 5 | Count `<=` 5 |
205
+
|`SQL Server Linux - Instance Down`| This alert is triggered when the SQL Server instance is down for 5 minutes. | Count `>` 0 | Count `<=` 0 |
206
+
|`SQL Server Linux - Insufficient Space`| This alert is triggered when the SQL Server instance cannot allocate a new page for the database due to insufficient disk space in the filegroup. | Count `>` 0 | Count `<=` 0 |
207
+
|`SQL Server Linux - Login Fail`| This alert is triggered when the user is unable to login to the SQL Server. | Count `>=` 1 | Count `<` 1 |
208
+
|`SQL Server Linux - Mirroring Error`| This alert is triggered when an error occurs in SQL Server mirroring. | Count `>=` 1 | Count `<` 1 |
0 commit comments