Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

EventOutcome field and value do not appear in CommonSecurityLog table

Open mlaraibkhan opened this issue 3 years ago • 5 comments

Microsoft CEF event mapping documentation says the Outcome field is mapped in the CommonSecurityLog table.

image

However, there's no Outcome field in the CommonSecurityLog schema. But there's one field called EventOutcome as shown in MS Sentinel below.

image

Although once a CEF event arrived in the Sentinel. The outcome value does not appear in the correct field, despite the outcome being set in the raw event. image

outcome value appears in AdditonalExtensions

Issue

The document version of CommonSecurityEvent schema mapping and MS Sentinel version of CommonSecurityEvent schema should be homogenous.

Bug-1

Raw events contain outcome values (success or failure) that appear in AdditionalExtension and not in the EventOutcome field.

Bug-2

Once the Raw event has the EventOutcome field, it completely disappears from the CommonSecurityEvent table.

mlaraibkhan avatar Dec 13 '22 13:12 mlaraibkhan

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Dec 13 '22 13:12 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Dec 13 '22 13:12 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Dec 14 '22 09:12 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 03 '23 09:01 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 10 '23 13:01 github-actions[bot]

@LaraibKhan555 The documentation for the schema change has been updated. Please refer the documentation links below: https://learn.microsoft.com/en-us/azure/sentinel/cef-name-mapping https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/commonsecuritylog Closing the issue as this is fixed.

v-amolpatil avatar Jan 20 '23 09:01 v-amolpatil

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 20 '23 09:01 github-actions[bot]