Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

TI map IP entity to FrontDoorHTTPLogs

Open Jeremyp87 opened this issue 2 years ago • 4 comments

Describe the solution you'd like I would like to be able to map TI to log analytics for traffic allowed trough Frontdoor without a Firewall rule hit. Traffic is already logged in FrontDoor Diagnostics and logging from AppService as well is pointless.

Describe alternatives you've considered Log from AppServiceHTTPLogs as well, would increase costs.

Relevant Analytic Rule: "TI map IP entity to AppServiceHTTPLogs"

Jeremyp87 avatar Jun 13 '22 13:06 Jeremyp87

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jun 13 '22 13:06 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Dec 22 '22 05:12 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 10 '23 12:01 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 10 '23 12:01 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Mar 20 '23 12:03 github-actions[bot]

Hi @Jeremyp87, We wanted to check on the status of Issue https://github.com/Azure/Azure-Sentinel/issues/5292 . The issue is pending for more than expected days. Please let us know if you need any assistance to review this Issue. As per our standard operating procedures if no response is received in the next 7 business days, we will close this Issue. Thank you for your cooperation.

v-rbajaj avatar Jun 07 '23 12:06 v-rbajaj

Since we have not received a response in the last 7 days, we are closing your issue as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation.

v-vdixit avatar Jun 15 '23 05:06 v-vdixit

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jun 15 '23 05:06 github-actions[bot]