AzureFlowLogs (v1.0.3)

This pack contains data normalization to XDM fields and timestamp ingestion for logs.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Cloud Services, Analytics & SIEM

Modeling rules (1)

README

<~XSIAM>

Overview

The network monitoring and diagnostic service in Microsoft Azure.
Providing tools to monitor, diagnose, and gain insights into network traffic and performance across Azure resources.
Key features include packet capture, connection troubleshooting, NSG flow logs, Network Traffic Analytics (NTA) flow logs, VNet flow logs, IP flow verification, and network topology visualization.

Pay Attention
This pack contains a beta Modeling Rule, which lets you process Network Traffic Analytics (NTA) logs to XDM fields.
Since the Modeling Rule’s NTA logs mapping is considered as beta, it might not contain some of the fields that are available from the logs.
We appreciate your feedback on the quality and usability of the Modeling Rule to help us identify issues, fix them, and continually improve.

This pack includes

Data normalization capabilities:

Supported log categories

Log Type Display Name
NSG Flow Logs Network Security Group Flow Event
Network Traffic Analytics Flow Logs NTA*

Supported Timestamp Formats

All of the supported log types support timestamp ingestion for the format %Y-%m-%dT%H:%M:%E*SZ.


Data Collection

NSG Flow Logs

In order to send NSG Flow log to XSIAM, enable the Azure Network Watcher integration.
For more information, see Ingest network flow logs from Microsoft Azure Network Watcher.

NTA Flow Logs

In order to send NTA Flow Logs to XSIAM, enable the Azure Event Hub integration.
For more information, see Ingest Logs from Microsoft Azure Event Hub.

Make sure the following fields are configured correctly for the integration:

Field Value
Log Format Raw
Vendor MSFT
Product Azure

</~XSIAM>