Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

/Solutions/Claroty/Parsers/ClarotyEvent.yaml does not parce out additional extensions for when threats are sent to Sentinal

Open thibMP opened this issue 1 year ago • 5 comments

Describe the bug Claroty delivers technical data related to threats triggered via a SNORT or Yara Rule but this log is partially parced. The following oare the Additional extensions that are delivered when a log is sent to Sentinal:

AdditionalExtensions

CtdSourceIp CtdDestinationIp CtdSourceMac CtdDestinationMac CtdSourceHost CtdDestinationHost CtdTimeGenerated CtdExternalId CtdDeviceExternalId CtdMessage CtdProtocol CtdCategory CtdSourceAssetType CtdDestinationAssetType CtdSourceZone CtdDestinationZone CtdAlertLink CtdAlertId CtdStoryId CtdEventTypeId CtdResolvedAs

https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Claroty/Parsers/ClarotyEvent.yaml

To Reproduce Steps to reproduce the behavior: Review the parcer and notice that the AdditionalExtensions are not configured to be parced out.

Expected behavior The extensions should be able to be queried.

thibMP avatar Jan 30 '24 10:01 thibMP

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 30 '24 10:01 github-actions[bot]

Hi @thibMP , Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 06/02/2024. Thanks!

v-muuppugund avatar Jan 31 '24 07:01 v-muuppugund

Hi @thibMP ,Could you please share sample data to email id ([email protected]),so can proceed with changes for additional extensions.

v-muuppugund avatar Feb 07 '24 03:02 v-muuppugund

Hi @v-muuppugund thanks I will get our SIEM engineering department to pull that info. Do you need raw data or is it ok if it is the info for what is in Sentinal today?

thibMP avatar Feb 07 '24 07:02 thibMP

Hi @v-muuppugund thanks I will get our SIEM engineering department to pull that info. Do you need raw data or is it ok if it is the info for what is in Sentinal today?

Hi @thibMP , Please share both the data will do some data analysis ,so will have data points for updating the parser.

v-muuppugund avatar Feb 07 '24 07:02 v-muuppugund

Hi @thibMP ,gentle reminder,Could you please share both the data will do some data analysis ,so will have data points for updating the parser.

v-muuppugund avatar Feb 11 '24 05:02 v-muuppugund

Hi @thibMP, since we have not received a response in the last 5 days, we are closing your issue #9860 as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation.

v-sudkharat avatar Feb 14 '24 11:02 v-sudkharat