mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'develop' into github_detections_improvement
This commit is contained in:
+8
-8
@@ -3,7 +3,7 @@ app:
|
||||
uid: 3449
|
||||
title: ES Content Updates
|
||||
appid: DA-ESS-ContentUpdate
|
||||
version: 5.0.0
|
||||
version: 5.1.0
|
||||
description: Explore the Analytic Stories included with ES Content Updates.
|
||||
prefix: ESCU
|
||||
label: ESCU
|
||||
@@ -30,11 +30,11 @@ splunk_api_username: null
|
||||
post_test_behavior: pause_on_failure
|
||||
apps:
|
||||
- uid: 1621
|
||||
title: Splunk Common Information Model (CIM)
|
||||
title: Splunk_SA_CIM
|
||||
appid: Splunk_SA_CIM
|
||||
version: 6.0.1
|
||||
version: 6.0.2
|
||||
description: description of app
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-common-information-model-cim_601.tgz
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-common-information-model-cim_602.tgz
|
||||
- uid: 6553
|
||||
title: Splunk Add-on for Okta Identity Cloud
|
||||
appid: Splunk_TA_okta_identity_cloud
|
||||
@@ -143,9 +143,9 @@ apps:
|
||||
- uid: 1876
|
||||
title: Splunk Add-on for AWS
|
||||
appid: Splunk_TA_aws
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
description: description of app
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-amazon-web-services-aws_790.tgz
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-amazon-web-services-aws_791.tgz
|
||||
- uid: 3088
|
||||
title: Splunk Add-on for Google Cloud Platform
|
||||
appid: SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM
|
||||
@@ -161,9 +161,9 @@ apps:
|
||||
- uid: 3110
|
||||
title: Splunk Add-on for Microsoft Cloud Services
|
||||
appid: SPLUNK_TA_MICROSOFT_CLOUD_SERVICES
|
||||
version: 5.4.2
|
||||
version: 5.4.3
|
||||
description: description of app
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-cloud-services_542.tgz
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-cloud-services_543.tgz
|
||||
- uid: 4055
|
||||
title: Splunk Add-on for Microsoft Office 365
|
||||
appid: SPLUNK_ADD_ON_FOR_MICROSOFT_OFFICE_365
|
||||
|
||||
@@ -10,4 +10,4 @@ separator: api.operation
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
|
||||
@@ -9,7 +9,7 @@ sourcetype: aws:cloudfront:accesslogs
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,4 +10,4 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -10,7 +10,7 @@ separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
|
||||
@@ -9,7 +9,7 @@ sourcetype: aws:cloudwatchlogs:vpcflow
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
fields:
|
||||
- _raw
|
||||
|
||||
@@ -9,7 +9,7 @@ sourcetype: aws:securityhub:finding
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.0
|
||||
version: 7.9.1
|
||||
fields:
|
||||
- _time
|
||||
- AwsAccountId
|
||||
|
||||
@@ -10,4 +10,4 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
version: 5.4.3
|
||||
|
||||
+1
-1
@@ -11,7 +11,7 @@ separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
|
||||
@@ -1,68 +1,69 @@
|
||||
name: Azure Active Directory Add member to role
|
||||
id: 1660d196-127f-4678-81b2-472d51711b07
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add member to role
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-04-28T16:39:51.9312625Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-04-28T16:39:51.9312625Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Add member to role", "operationVersion": "1.0", "category": "AuditLogs",
|
||||
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
|
||||
0, "callerIpAddress": "52.177.250.168", "correlationId": "b425f2d7-2245-4952-b599-61dff8054f2b",
|
||||
|
||||
@@ -1,73 +1,74 @@
|
||||
name: Azure Active Directory Add owner to application
|
||||
id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add owner to application
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-06-20T15:54:13.2420879Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-06-20T15:54:13.2420879Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Add owner to application", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "durationMs": 0, "callerIpAddress": "20.190.135.43", "correlationId": "231de5d4-2156-433a-8163-48956bdaa040",
|
||||
|
||||
@@ -1,68 +1,69 @@
|
||||
name: Azure Active Directory Add service principal
|
||||
id: fd89d337-e4c0-4162-ad13-bca36f096fe6
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add service principal
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2024-02-07T22:31:14.4970418Z", "resourceId": "/tenants/a417c578-c7ee-480d-a225-d48057e74df5/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2024-02-07T22:31:14.4970418Z", "resourceId": "/tenants/a417c578-c7ee-480d-a225-d48057e74df5/providers/Microsoft.aadiam",
|
||||
"operationName": "Add service principal", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "a417c578-c7ee-480d-a225-d48057e74df5", "resultSignature":
|
||||
"None", "durationMs": 0, "correlationId": "ea473f15-64b3-435a-a885-6ee3908919e2",
|
||||
|
||||
@@ -1,68 +1,69 @@
|
||||
name: Azure Active Directory Add unverified domain
|
||||
id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add unverified domain
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-26T13:45:54.1582053Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-07-26T13:45:54.1582053Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Add unverified domain", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "durationMs": 0, "callerIpAddress": "2601:646:a000:200:6419:f55c:946d:17d1",
|
||||
|
||||
@@ -1,73 +1,74 @@
|
||||
name: Azure Active Directory Consent to application
|
||||
id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Consent to application
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-10-27T16:14:14.9747033Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-10-27T16:14:14.9747033Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
|
||||
"operationName": "Consent to application", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature":
|
||||
"None", "resultDescription": "Microsoft.Online.Security.UserConsentBlockedForRiskyAppsException",
|
||||
|
||||
@@ -1,67 +1,68 @@
|
||||
name: Azure Active Directory Disable Strong Authentication
|
||||
id: 8f31966d-c496-496d-8837-f7fd11f31255
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Disable Strong Authentication
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-11T00:01:35.0251899Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-07-11T00:01:35.0251899Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Disable Strong Authentication", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "durationMs": 0, "correlationId": "7e3ee05c-ce4f-4ff1-8230-55555c25c97e",
|
||||
|
||||
@@ -1,68 +1,69 @@
|
||||
name: Azure Active Directory Enable account
|
||||
id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Enable account
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-24T14:28:15.2223487Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-07-24T14:28:15.2223487Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Enable account", "operationVersion": "1.0", "category": "AuditLogs",
|
||||
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
|
||||
0, "callerIpAddress": "2601:646:a000:200:b0ee:600c:de8a:c7d5", "correlationId":
|
||||
|
||||
@@ -1,67 +1,68 @@
|
||||
name: Azure Active Directory Invite external user
|
||||
id: d3818bd5-f283-4518-8b67-df19240c3e40
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Invite external user
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-13T00:29:59.5100003Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-07-13T00:29:59.5100003Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Invite external user", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "durationMs": 0, "callerIpAddress": "40.126.4.40", "correlationId": "e7d580a6-eaac-4f82-843c-40b0b5f3cf99",
|
||||
|
||||
@@ -1,68 +1,69 @@
|
||||
name: Azure Active Directory Reset password (by admin)
|
||||
id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Reset password (by admin)
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-24T14:28:55.0648789Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-07-24T14:28:55.0648789Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Reset password (by admin)", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "resultDescription": "None", "durationMs": 0, "callerIpAddress": "40.81.4.144",
|
||||
|
||||
@@ -1,68 +1,69 @@
|
||||
name: Azure Active Directory Set domain authentication
|
||||
id: e7bcdab9-908c-40ab-ba38-5db54fa87750
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Set domain authentication
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-26T13:44:59.0372448Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-07-26T13:44:59.0372448Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Set domain authentication", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "durationMs": 0, "callerIpAddress": "2601:646:a000:200:6419:f55c:946d:17d1",
|
||||
|
||||
@@ -1,118 +1,119 @@
|
||||
name: Azure Active Directory Sign-in activity
|
||||
id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Sign-in activity
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- identity
|
||||
- index
|
||||
- linecount
|
||||
- location
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.alternateSignInName
|
||||
- properties.appDisplayName
|
||||
- properties.appId
|
||||
- properties.appServicePrincipalId
|
||||
- properties.authenticationDetails{}.RequestSequence
|
||||
- properties.authenticationDetails{}.StatusSequence
|
||||
- properties.authenticationDetails{}.authenticationMethod
|
||||
- properties.authenticationDetails{}.authenticationMethodDetail
|
||||
- properties.authenticationDetails{}.authenticationStepDateTime
|
||||
- properties.authenticationDetails{}.authenticationStepRequirement
|
||||
- properties.authenticationDetails{}.authenticationStepResultDetail
|
||||
- properties.authenticationDetails{}.succeeded
|
||||
- properties.authenticationProcessingDetails{}.key
|
||||
- properties.authenticationProcessingDetails{}.value
|
||||
- properties.authenticationProtocol
|
||||
- properties.authenticationRequirement
|
||||
- properties.authenticationRequirementPolicies{}.detail
|
||||
- properties.authenticationRequirementPolicies{}.requirementProvider
|
||||
- properties.autonomousSystemNumber
|
||||
- properties.clientAppUsed
|
||||
- properties.clientCredentialType
|
||||
- properties.conditionalAccessStatus
|
||||
- properties.correlationId
|
||||
- properties.createdDateTime
|
||||
- properties.crossTenantAccessType
|
||||
- properties.deviceDetail.deviceId
|
||||
- properties.deviceDetail.operatingSystem
|
||||
- properties.flaggedForReview
|
||||
- properties.homeTenantId
|
||||
- properties.id
|
||||
- properties.incomingTokenType
|
||||
- properties.ipAddress
|
||||
- properties.isInteractive
|
||||
- properties.isTenantRestricted
|
||||
- properties.location.city
|
||||
- properties.location.countryOrRegion
|
||||
- properties.location.geoCoordinates.latitude
|
||||
- properties.location.geoCoordinates.longitude
|
||||
- properties.location.state
|
||||
- properties.originalRequestId
|
||||
- properties.originalTransferMethod
|
||||
- properties.processingTimeInMilliseconds
|
||||
- properties.resourceDisplayName
|
||||
- properties.resourceId
|
||||
- properties.resourceServicePrincipalId
|
||||
- properties.resourceTenantId
|
||||
- properties.riskDetail
|
||||
- properties.riskLevelAggregated
|
||||
- properties.riskLevelDuringSignIn
|
||||
- properties.riskState
|
||||
- properties.rngcStatus
|
||||
- properties.servicePrincipalId
|
||||
- properties.signInIdentifier
|
||||
- properties.signInTokenProtectionStatus
|
||||
- properties.ssoExtensionVersion
|
||||
- properties.status.additionalDetails
|
||||
- properties.status.errorCode
|
||||
- properties.status.failureReason
|
||||
- properties.tenantId
|
||||
- properties.tokenIssuerName
|
||||
- properties.tokenIssuerType
|
||||
- properties.uniqueTokenIdentifier
|
||||
- properties.userAgent
|
||||
- properties.userDisplayName
|
||||
- properties.userId
|
||||
- properties.userPrincipalName
|
||||
- properties.userType
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- resultType
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-10-24T20:13:31.4449614Z", "resourceId": "/tenants/887c9144-28b8-431b-885b-764fdeefcf62/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- identity
|
||||
- index
|
||||
- linecount
|
||||
- location
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.alternateSignInName
|
||||
- properties.appDisplayName
|
||||
- properties.appId
|
||||
- properties.appServicePrincipalId
|
||||
- properties.authenticationDetails{}.RequestSequence
|
||||
- properties.authenticationDetails{}.StatusSequence
|
||||
- properties.authenticationDetails{}.authenticationMethod
|
||||
- properties.authenticationDetails{}.authenticationMethodDetail
|
||||
- properties.authenticationDetails{}.authenticationStepDateTime
|
||||
- properties.authenticationDetails{}.authenticationStepRequirement
|
||||
- properties.authenticationDetails{}.authenticationStepResultDetail
|
||||
- properties.authenticationDetails{}.succeeded
|
||||
- properties.authenticationProcessingDetails{}.key
|
||||
- properties.authenticationProcessingDetails{}.value
|
||||
- properties.authenticationProtocol
|
||||
- properties.authenticationRequirement
|
||||
- properties.authenticationRequirementPolicies{}.detail
|
||||
- properties.authenticationRequirementPolicies{}.requirementProvider
|
||||
- properties.autonomousSystemNumber
|
||||
- properties.clientAppUsed
|
||||
- properties.clientCredentialType
|
||||
- properties.conditionalAccessStatus
|
||||
- properties.correlationId
|
||||
- properties.createdDateTime
|
||||
- properties.crossTenantAccessType
|
||||
- properties.deviceDetail.deviceId
|
||||
- properties.deviceDetail.operatingSystem
|
||||
- properties.flaggedForReview
|
||||
- properties.homeTenantId
|
||||
- properties.id
|
||||
- properties.incomingTokenType
|
||||
- properties.ipAddress
|
||||
- properties.isInteractive
|
||||
- properties.isTenantRestricted
|
||||
- properties.location.city
|
||||
- properties.location.countryOrRegion
|
||||
- properties.location.geoCoordinates.latitude
|
||||
- properties.location.geoCoordinates.longitude
|
||||
- properties.location.state
|
||||
- properties.originalRequestId
|
||||
- properties.originalTransferMethod
|
||||
- properties.processingTimeInMilliseconds
|
||||
- properties.resourceDisplayName
|
||||
- properties.resourceId
|
||||
- properties.resourceServicePrincipalId
|
||||
- properties.resourceTenantId
|
||||
- properties.riskDetail
|
||||
- properties.riskLevelAggregated
|
||||
- properties.riskLevelDuringSignIn
|
||||
- properties.riskState
|
||||
- properties.rngcStatus
|
||||
- properties.servicePrincipalId
|
||||
- properties.signInIdentifier
|
||||
- properties.signInTokenProtectionStatus
|
||||
- properties.ssoExtensionVersion
|
||||
- properties.status.additionalDetails
|
||||
- properties.status.errorCode
|
||||
- properties.status.failureReason
|
||||
- properties.tenantId
|
||||
- properties.tokenIssuerName
|
||||
- properties.tokenIssuerType
|
||||
- properties.uniqueTokenIdentifier
|
||||
- properties.userAgent
|
||||
- properties.userDisplayName
|
||||
- properties.userId
|
||||
- properties.userPrincipalName
|
||||
- properties.userType
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- resultType
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-10-24T20:13:31.4449614Z", "resourceId": "/tenants/887c9144-28b8-431b-885b-764fdeefcf62/providers/Microsoft.aadiam",
|
||||
"operationName": "Sign-in activity", "operationVersion": "1.0", "category": "SignInLogs",
|
||||
"tenantId": "887c9144-28b8-431b-885b-764fdeefcf62", "resultType": "50076", "resultSignature":
|
||||
"None", "resultDescription": "Due to a configuration change made by your administrator,
|
||||
|
||||
@@ -1,68 +1,69 @@
|
||||
name: Azure Active Directory Update application
|
||||
id: 2c08188a-ba25-496e-87c7-803cf28b6c90
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Update application
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2024-01-29T21:31:03.0102031Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2024-01-29T21:31:03.0102031Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
|
||||
"operationName": "Update application", "operationVersion": "1.0", "category": "AuditLogs",
|
||||
"tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature": "None", "durationMs":
|
||||
0, "correlationId": "a5396d2b-fcf6-41e7-9219-c6239f1298e3", "Level": 4, "properties":
|
||||
|
||||
@@ -1,69 +1,70 @@
|
||||
name: Azure Active Directory Update authorization policy
|
||||
id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Update authorization policy
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-10-26T19:22:20.2814027Z", "resourceId": "/tenants/5f210575-a69b-41a7-b623-3f6d79ccd432/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-10-26T19:22:20.2814027Z", "resourceId": "/tenants/5f210575-a69b-41a7-b623-3f6d79ccd432/providers/Microsoft.aadiam",
|
||||
"operationName": "Update authorization policy", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "5f210575-a69b-41a7-b623-3f6d79ccd432", "resultSignature":
|
||||
"None", "durationMs": 0, "callerIpAddress": "1.2.3.4", "correlationId": "cc46d719-4c0f-4b78-8795-b0d6ca5b2065",
|
||||
|
||||
@@ -1,70 +1,71 @@
|
||||
name: Azure Active Directory Update user
|
||||
id: 5495c90a-047c-4b8e-b2fe-1db6282d3872
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Update user
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-24T14:28:15.2233481Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-07-24T14:28:15.2233481Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Update user", "operationVersion": "1.0", "category": "AuditLogs",
|
||||
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
|
||||
0, "callerIpAddress": "2601:646:a000:200:b0ee:600c:de8a:c7d5", "correlationId":
|
||||
|
||||
@@ -1,67 +1,69 @@
|
||||
name: Azure Active Directory User registered security info
|
||||
id: b63240de-8a01-4ba8-8987-89d18d4b375d
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory User registered security
|
||||
description:
|
||||
Data source object for Azure Active Directory User registered security
|
||||
info
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-01-30T21:11:30.8690619Z", "resourceId": "/tenants/91da745f-8abb-4a7d-ba94-5667c6f9e01a/providers/Microsoft.aadiam",
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"time": "2023-01-30T21:11:30.8690619Z", "resourceId": "/tenants/91da745f-8abb-4a7d-ba94-5667c6f9e01a/providers/Microsoft.aadiam",
|
||||
"operationName": "User registered security info", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "91da745f-8abb-4a7d-ba94-5667c6f9e01a", "resultSignature":
|
||||
"None", "resultDescription": "User registered App Password", "durationMs": 0, "callerIpAddress":
|
||||
|
||||
@@ -1,107 +1,109 @@
|
||||
name: Azure Audit Create or Update an Azure Automation account
|
||||
id: 2ab182e7-feda-4249-9418-32710b55a885
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Audit Create or Update an Azure Automation
|
||||
description:
|
||||
Data source object for Azure Audit Create or Update an Azure Automation
|
||||
account
|
||||
source: mscs:azure:audit
|
||||
sourcetype: mscs:azure:audit
|
||||
separator: operationName.localizedValue
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- authorization.action
|
||||
- authorization.scope
|
||||
- caller
|
||||
- channels
|
||||
- claims.aio
|
||||
- claims.altsecid
|
||||
- claims.appid
|
||||
- claims.appidacr
|
||||
- claims.aud
|
||||
- claims.exp
|
||||
- claims.groups
|
||||
- claims.http://schemas.microsoft.com/claims/authnclassreference
|
||||
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
|
||||
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
|
||||
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
|
||||
- claims.http://schemas.microsoft.com/identity/claims/scope
|
||||
- claims.http://schemas.microsoft.com/identity/claims/tenantid
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
|
||||
- claims.iat
|
||||
- claims.ipaddr
|
||||
- claims.iss
|
||||
- claims.name
|
||||
- claims.nbf
|
||||
- claims.puid
|
||||
- claims.rh
|
||||
- claims.uti
|
||||
- claims.ver
|
||||
- claims.wids
|
||||
- claims.xms_tcdt
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventDataId
|
||||
- eventName.localizedValue
|
||||
- eventName.value
|
||||
- eventSource.localizedValue
|
||||
- eventSource.value
|
||||
- eventTimestamp
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- level
|
||||
- linecount
|
||||
- object
|
||||
- object_id
|
||||
- object_path
|
||||
- operationId
|
||||
- operationName.localizedValue
|
||||
- operationName.value
|
||||
- product
|
||||
- properties.entity
|
||||
- properties.eventCategory
|
||||
- properties.hierarchy
|
||||
- properties.message
|
||||
- punct
|
||||
- resourceGroupName
|
||||
- resourceProviderName.localizedValue
|
||||
- resourceProviderName.value
|
||||
- resourceUri
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- status
|
||||
- status.localizedValue
|
||||
- status.value
|
||||
- subStatus.value
|
||||
- submissionTimestamp
|
||||
- subscriptionId
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
- vendor_res_code
|
||||
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/write",
|
||||
- _time
|
||||
- authorization.action
|
||||
- authorization.scope
|
||||
- caller
|
||||
- channels
|
||||
- claims.aio
|
||||
- claims.altsecid
|
||||
- claims.appid
|
||||
- claims.appidacr
|
||||
- claims.aud
|
||||
- claims.exp
|
||||
- claims.groups
|
||||
- claims.http://schemas.microsoft.com/claims/authnclassreference
|
||||
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
|
||||
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
|
||||
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
|
||||
- claims.http://schemas.microsoft.com/identity/claims/scope
|
||||
- claims.http://schemas.microsoft.com/identity/claims/tenantid
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
|
||||
- claims.iat
|
||||
- claims.ipaddr
|
||||
- claims.iss
|
||||
- claims.name
|
||||
- claims.nbf
|
||||
- claims.puid
|
||||
- claims.rh
|
||||
- claims.uti
|
||||
- claims.ver
|
||||
- claims.wids
|
||||
- claims.xms_tcdt
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventDataId
|
||||
- eventName.localizedValue
|
||||
- eventName.value
|
||||
- eventSource.localizedValue
|
||||
- eventSource.value
|
||||
- eventTimestamp
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- level
|
||||
- linecount
|
||||
- object
|
||||
- object_id
|
||||
- object_path
|
||||
- operationId
|
||||
- operationName.localizedValue
|
||||
- operationName.value
|
||||
- product
|
||||
- properties.entity
|
||||
- properties.eventCategory
|
||||
- properties.hierarchy
|
||||
- properties.message
|
||||
- punct
|
||||
- resourceGroupName
|
||||
- resourceProviderName.localizedValue
|
||||
- resourceProviderName.value
|
||||
- resourceUri
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- status
|
||||
- status.localizedValue
|
||||
- status.value
|
||||
- subStatus.value
|
||||
- submissionTimestamp
|
||||
- subscriptionId
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
- vendor_res_code
|
||||
example_log:
|
||||
'{"authorization": {"action": "Microsoft.Automation/automationAccounts/write",
|
||||
"scope": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount"},
|
||||
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
|
||||
"iss": "https://sts.windows.net/ad251139-d600-4f45-a8ba-9f6ca1e5a93d/", "iat": "1661179930",
|
||||
|
||||
@@ -1,107 +1,109 @@
|
||||
name: Azure Audit Create or Update an Azure Automation Runbook
|
||||
id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Audit Create or Update an Azure Automation
|
||||
description:
|
||||
Data source object for Azure Audit Create or Update an Azure Automation
|
||||
Runbook
|
||||
source: mscs:azure:audit
|
||||
sourcetype: mscs:azure:audit
|
||||
separator: operationName.localizedValue
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- authorization.action
|
||||
- authorization.scope
|
||||
- caller
|
||||
- channels
|
||||
- claims.aio
|
||||
- claims.altsecid
|
||||
- claims.appid
|
||||
- claims.appidacr
|
||||
- claims.aud
|
||||
- claims.exp
|
||||
- claims.groups
|
||||
- claims.http://schemas.microsoft.com/claims/authnclassreference
|
||||
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
|
||||
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
|
||||
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
|
||||
- claims.http://schemas.microsoft.com/identity/claims/scope
|
||||
- claims.http://schemas.microsoft.com/identity/claims/tenantid
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
|
||||
- claims.iat
|
||||
- claims.ipaddr
|
||||
- claims.iss
|
||||
- claims.name
|
||||
- claims.nbf
|
||||
- claims.puid
|
||||
- claims.rh
|
||||
- claims.uti
|
||||
- claims.ver
|
||||
- claims.wids
|
||||
- claims.xms_tcdt
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventDataId
|
||||
- eventName.localizedValue
|
||||
- eventName.value
|
||||
- eventSource.localizedValue
|
||||
- eventSource.value
|
||||
- eventTimestamp
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- level
|
||||
- linecount
|
||||
- object
|
||||
- object_id
|
||||
- object_path
|
||||
- operationId
|
||||
- operationName.localizedValue
|
||||
- operationName.value
|
||||
- product
|
||||
- properties.entity
|
||||
- properties.eventCategory
|
||||
- properties.hierarchy
|
||||
- properties.message
|
||||
- punct
|
||||
- resourceGroupName
|
||||
- resourceProviderName.localizedValue
|
||||
- resourceProviderName.value
|
||||
- resourceUri
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- status
|
||||
- status.localizedValue
|
||||
- status.value
|
||||
- subStatus.value
|
||||
- submissionTimestamp
|
||||
- subscriptionId
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
- vendor_res_code
|
||||
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/runbooks/write",
|
||||
- _time
|
||||
- authorization.action
|
||||
- authorization.scope
|
||||
- caller
|
||||
- channels
|
||||
- claims.aio
|
||||
- claims.altsecid
|
||||
- claims.appid
|
||||
- claims.appidacr
|
||||
- claims.aud
|
||||
- claims.exp
|
||||
- claims.groups
|
||||
- claims.http://schemas.microsoft.com/claims/authnclassreference
|
||||
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
|
||||
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
|
||||
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
|
||||
- claims.http://schemas.microsoft.com/identity/claims/scope
|
||||
- claims.http://schemas.microsoft.com/identity/claims/tenantid
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
|
||||
- claims.iat
|
||||
- claims.ipaddr
|
||||
- claims.iss
|
||||
- claims.name
|
||||
- claims.nbf
|
||||
- claims.puid
|
||||
- claims.rh
|
||||
- claims.uti
|
||||
- claims.ver
|
||||
- claims.wids
|
||||
- claims.xms_tcdt
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventDataId
|
||||
- eventName.localizedValue
|
||||
- eventName.value
|
||||
- eventSource.localizedValue
|
||||
- eventSource.value
|
||||
- eventTimestamp
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- level
|
||||
- linecount
|
||||
- object
|
||||
- object_id
|
||||
- object_path
|
||||
- operationId
|
||||
- operationName.localizedValue
|
||||
- operationName.value
|
||||
- product
|
||||
- properties.entity
|
||||
- properties.eventCategory
|
||||
- properties.hierarchy
|
||||
- properties.message
|
||||
- punct
|
||||
- resourceGroupName
|
||||
- resourceProviderName.localizedValue
|
||||
- resourceProviderName.value
|
||||
- resourceUri
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- status
|
||||
- status.localizedValue
|
||||
- status.value
|
||||
- subStatus.value
|
||||
- submissionTimestamp
|
||||
- subscriptionId
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
- vendor_res_code
|
||||
example_log:
|
||||
'{"authorization": {"action": "Microsoft.Automation/automationAccounts/runbooks/write",
|
||||
"scope": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourceGroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook"},
|
||||
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
|
||||
"iss": "https://sts.windows.net/ad251139-d600-4f45-a8ba-9f6ca1e5a93d/", "iat": "1661194261",
|
||||
|
||||
@@ -1,116 +1,118 @@
|
||||
name: Azure Audit Create or Update an Azure Automation webhook
|
||||
id: 575faeb2-09d0-4849-b1f6-eae241f26ff2
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
date: "2024-07-18"
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Audit Create or Update an Azure Automation
|
||||
description:
|
||||
Data source object for Azure Audit Create or Update an Azure Automation
|
||||
webhook
|
||||
source: mscs:azure:audit
|
||||
sourcetype: mscs:azure:audit
|
||||
separator: operationName.localizedValue
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- _time
|
||||
- authorization.action
|
||||
- authorization.scope
|
||||
- caller
|
||||
- channels
|
||||
- claims.aio
|
||||
- claims.altsecid
|
||||
- claims.appid
|
||||
- claims.appidacr
|
||||
- claims.aud
|
||||
- claims.exp
|
||||
- claims.groups
|
||||
- claims.http://schemas.microsoft.com/claims/authnclassreference
|
||||
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
|
||||
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
|
||||
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
|
||||
- claims.http://schemas.microsoft.com/identity/claims/scope
|
||||
- claims.http://schemas.microsoft.com/identity/claims/tenantid
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
|
||||
- claims.iat
|
||||
- claims.ipaddr
|
||||
- claims.iss
|
||||
- claims.name
|
||||
- claims.nbf
|
||||
- claims.puid
|
||||
- claims.rh
|
||||
- claims.uti
|
||||
- claims.ver
|
||||
- claims.wids
|
||||
- claims.xms_tcdt
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventDataId
|
||||
- eventName.localizedValue
|
||||
- eventName.value
|
||||
- eventSource.localizedValue
|
||||
- eventSource.value
|
||||
- eventTimestamp
|
||||
- host
|
||||
- httpRequest.clientIpAddress
|
||||
- httpRequest.clientRequestId
|
||||
- httpRequest.method
|
||||
- id
|
||||
- index
|
||||
- level
|
||||
- linecount
|
||||
- object
|
||||
- object_id
|
||||
- object_path
|
||||
- operationId
|
||||
- operationName.localizedValue
|
||||
- operationName.value
|
||||
- product
|
||||
- properties.entity
|
||||
- properties.eventCategory
|
||||
- properties.hierarchy
|
||||
- properties.message
|
||||
- properties.serviceRequestId
|
||||
- properties.statusCode
|
||||
- punct
|
||||
- resourceGroupName
|
||||
- resourceProviderName.localizedValue
|
||||
- resourceProviderName.value
|
||||
- resourceUri
|
||||
- result
|
||||
- result_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- status
|
||||
- status.localizedValue
|
||||
- status.value
|
||||
- subStatus.localizedValue
|
||||
- subStatus.value
|
||||
- submissionTimestamp
|
||||
- subscriptionId
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
- vendor_res_code
|
||||
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/webhooks/write",
|
||||
- _time
|
||||
- authorization.action
|
||||
- authorization.scope
|
||||
- caller
|
||||
- channels
|
||||
- claims.aio
|
||||
- claims.altsecid
|
||||
- claims.appid
|
||||
- claims.appidacr
|
||||
- claims.aud
|
||||
- claims.exp
|
||||
- claims.groups
|
||||
- claims.http://schemas.microsoft.com/claims/authnclassreference
|
||||
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
|
||||
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
|
||||
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
|
||||
- claims.http://schemas.microsoft.com/identity/claims/scope
|
||||
- claims.http://schemas.microsoft.com/identity/claims/tenantid
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
|
||||
- claims.iat
|
||||
- claims.ipaddr
|
||||
- claims.iss
|
||||
- claims.name
|
||||
- claims.nbf
|
||||
- claims.puid
|
||||
- claims.rh
|
||||
- claims.uti
|
||||
- claims.ver
|
||||
- claims.wids
|
||||
- claims.xms_tcdt
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventDataId
|
||||
- eventName.localizedValue
|
||||
- eventName.value
|
||||
- eventSource.localizedValue
|
||||
- eventSource.value
|
||||
- eventTimestamp
|
||||
- host
|
||||
- httpRequest.clientIpAddress
|
||||
- httpRequest.clientRequestId
|
||||
- httpRequest.method
|
||||
- id
|
||||
- index
|
||||
- level
|
||||
- linecount
|
||||
- object
|
||||
- object_id
|
||||
- object_path
|
||||
- operationId
|
||||
- operationName.localizedValue
|
||||
- operationName.value
|
||||
- product
|
||||
- properties.entity
|
||||
- properties.eventCategory
|
||||
- properties.hierarchy
|
||||
- properties.message
|
||||
- properties.serviceRequestId
|
||||
- properties.statusCode
|
||||
- punct
|
||||
- resourceGroupName
|
||||
- resourceProviderName.localizedValue
|
||||
- resourceProviderName.value
|
||||
- resourceUri
|
||||
- result
|
||||
- result_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- status
|
||||
- status.localizedValue
|
||||
- status.value
|
||||
- subStatus.localizedValue
|
||||
- subStatus.value
|
||||
- submissionTimestamp
|
||||
- subscriptionId
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
- vendor_res_code
|
||||
example_log:
|
||||
'{"authorization": {"action": "Microsoft.Automation/automationAccounts/webhooks/write",
|
||||
"scope": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook"},
|
||||
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
|
||||
"iss": "https://sts.windows.net/ad251139-d600-4f45-a8ba-9f6ca1e5a93d/", "iat": "1661287859",
|
||||
|
||||
@@ -1,9 +1,10 @@
|
||||
name: Azure Monitor Activity
|
||||
id: 1997a515-a61a-4f78-ada9-54af34c764f2
|
||||
version: 1
|
||||
date: '2025-01-13'
|
||||
date: "2025-01-13"
|
||||
author: Bhavin Patel, Splunk
|
||||
description: Data source object for Azure Monitor Activity. The Splunk Add-on for
|
||||
description:
|
||||
Data source object for Azure Monitor Activity. The Splunk Add-on for
|
||||
Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure
|
||||
EventHub. To configure this logging, visit Intune > Tenant administration > Diagnostic
|
||||
settings > Add diagnostic settings & send events to the activity audit event hub.
|
||||
@@ -11,92 +12,93 @@ source: Azure AD
|
||||
sourcetype: azure:monitor:activity
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.2
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.4.3
|
||||
fields:
|
||||
- column
|
||||
- action
|
||||
- category
|
||||
- change_type
|
||||
- command
|
||||
- correlationId
|
||||
- dataset_name
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventtype
|
||||
- host
|
||||
- identity
|
||||
- image_id
|
||||
- index
|
||||
- instance_type
|
||||
- linecount
|
||||
- object
|
||||
- object_attrs
|
||||
- object_category
|
||||
- object_id
|
||||
- object_path
|
||||
- operationName
|
||||
- properties.ActivityDate
|
||||
- properties.ActivityResultStatus
|
||||
- properties.ActivityType
|
||||
- properties.Actor.ActorType
|
||||
- properties.Actor.Application
|
||||
- properties.Actor.ApplicationName
|
||||
- properties.Actor.IsDelegatedAdmin
|
||||
- properties.Actor.Name
|
||||
- properties.Actor.ObjectId
|
||||
- properties.Actor.PartnerTenantId
|
||||
- properties.Actor.UPN
|
||||
- properties.Actor.UserPermissions{}
|
||||
- properties.AdditionalDetails
|
||||
- properties.AuditEventId
|
||||
- properties.Category
|
||||
- properties.RelationId
|
||||
- properties.TargetDisplayNames{}
|
||||
- properties.TargetObjectIds{}
|
||||
- properties.Targets{}.ModifiedProperties{}.Name
|
||||
- properties.Targets{}.ModifiedProperties{}.New
|
||||
- properties.Targets{}.ModifiedProperties{}.Old
|
||||
- properties.Targets{}.Name
|
||||
- punct
|
||||
- resourceId
|
||||
- resource_provider
|
||||
- response_body
|
||||
- result
|
||||
- resultDescription
|
||||
- resultType
|
||||
- result_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- splunk_server_group
|
||||
- src
|
||||
- status
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- tag::object_category
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
- _time
|
||||
example_log: '{"time": "2024-04-29T13:30:28.8622000Z", "tenantId": "26db52ee-c1b5-4c96-a0d4-129e25dc0388",
|
||||
- column
|
||||
- action
|
||||
- category
|
||||
- change_type
|
||||
- command
|
||||
- correlationId
|
||||
- dataset_name
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventtype
|
||||
- host
|
||||
- identity
|
||||
- image_id
|
||||
- index
|
||||
- instance_type
|
||||
- linecount
|
||||
- object
|
||||
- object_attrs
|
||||
- object_category
|
||||
- object_id
|
||||
- object_path
|
||||
- operationName
|
||||
- properties.ActivityDate
|
||||
- properties.ActivityResultStatus
|
||||
- properties.ActivityType
|
||||
- properties.Actor.ActorType
|
||||
- properties.Actor.Application
|
||||
- properties.Actor.ApplicationName
|
||||
- properties.Actor.IsDelegatedAdmin
|
||||
- properties.Actor.Name
|
||||
- properties.Actor.ObjectId
|
||||
- properties.Actor.PartnerTenantId
|
||||
- properties.Actor.UPN
|
||||
- properties.Actor.UserPermissions{}
|
||||
- properties.AdditionalDetails
|
||||
- properties.AuditEventId
|
||||
- properties.Category
|
||||
- properties.RelationId
|
||||
- properties.TargetDisplayNames{}
|
||||
- properties.TargetObjectIds{}
|
||||
- properties.Targets{}.ModifiedProperties{}.Name
|
||||
- properties.Targets{}.ModifiedProperties{}.New
|
||||
- properties.Targets{}.ModifiedProperties{}.Old
|
||||
- properties.Targets{}.Name
|
||||
- punct
|
||||
- resourceId
|
||||
- resource_provider
|
||||
- response_body
|
||||
- result
|
||||
- resultDescription
|
||||
- resultType
|
||||
- result_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- splunk_server_group
|
||||
- src
|
||||
- status
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- tag::object_category
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
- _time
|
||||
example_log:
|
||||
'{"time": "2024-04-29T13:30:28.8622000Z", "tenantId": "26db52ee-c1b5-4c96-a0d4-129e25dc0388",
|
||||
"category": "AuditLogs", "operationName": "createDeviceHealthScript DeviceHealthScript",
|
||||
"properties": {"ActivityDate": "4/29/2024 1:30:28 PM", "ActivityResultStatus": 1,
|
||||
"ActivityType": 0, "Actor": {"ActorType": 1, "Application": "5926fc8e-304e-4f59-8bed-58ca97cc39a4",
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
name: Splunk CIM
|
||||
id: d3dd8270-7e1c-4bcd-8f3a-e5ec4a0e740a
|
||||
version: 1
|
||||
date: '2025-01-14'
|
||||
author: Bhavin Patel, Splunk
|
||||
description: Data source object for Splunk CIM
|
||||
source: not_applicable
|
||||
sourcetype: not_applicable
|
||||
supported_TA:
|
||||
- name: Splunk_SA_CIM
|
||||
url: https://splunkbase.splunk.com/app/1621
|
||||
version: 6.0.2
|
||||
@@ -1,8 +1,8 @@
|
||||
name: Linux Proxy Socks Curl
|
||||
id: bd596c22-ad1e-44fc-b242-817253ce8b08
|
||||
version: 6
|
||||
date: '2024-11-13'
|
||||
author: Michael Haag, Splunk
|
||||
version: 7
|
||||
date: '2025-02-19'
|
||||
author: Michael Haag, Splunk, 0xC0FFEEEE, Github Community
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the use of the `curl` command with proxy-related
|
||||
@@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
|
||||
"*--preproxy *", "--proxy*") by Processes.dest Processes.user Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `linux_proxy_socks_curl_filter`'
|
||||
| where match(process, "-x\s") OR match(process, "(?i)socks\d\w?:\/\/|--(pre)?proxy") | `linux_proxy_socks_curl_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows InstallUtil Remote Network Connection
|
||||
id: 4fbf9270-43da-11ec-9486-acde48001122
|
||||
version: 10
|
||||
date: '2025-02-10'
|
||||
version: 11
|
||||
date: '2025-02-22'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -16,15 +16,25 @@ description: The following analytic detects the Windows InstallUtil.exe binary m
|
||||
of this activity.
|
||||
data_source:
|
||||
- Sysmon EventID 1 AND Sysmon EventID 3
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where `process_installutil` by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.dest Processes.user Processes.process_path Processes.process Processes.parent_process_name
|
||||
Processes.original_file_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | join process_id [| tstats `security_content_summariesonly`
|
||||
count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port !=
|
||||
0 by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port | `drop_dm_object_name(All_Traffic)`
|
||||
| rename dest as C2 ] | table _time user dest parent_process_name process_name process_path
|
||||
process process_id dest_port C2 | `windows_installutil_remote_network_connection_filter`'
|
||||
search: |-
|
||||
| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where `process_installutil` by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.dest Processes.user Processes.process_path Processes.process Processes.parent_process_name
|
||||
Processes.original_file_name
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| join process_id dest
|
||||
[| tstats `security_content_summariesonly`
|
||||
count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port !=
|
||||
0 by All_Traffic.process_id All_Traffic.dest All_Traffic.dest_port All_Traffic.src
|
||||
| `drop_dm_object_name(All_Traffic)`
|
||||
| rename dest as command_and_control
|
||||
| rename src as dest]
|
||||
| table _time user src dest parent_process_name process_name process_path process process_id dest_port command_and_control
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(process) as process values(command_and_control) as command_and_control by user dest process_name process_id dest_port parent_process_name
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`| `windows_installutil_remote_network_connection_filter`
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
@@ -68,6 +78,8 @@ rba:
|
||||
type: parent_process_name
|
||||
- field: process_name
|
||||
type: process_name
|
||||
- field: command_and_control
|
||||
type: ip_address
|
||||
tags:
|
||||
analytic_story:
|
||||
- Living Off The Land
|
||||
|
||||
Reference in New Issue
Block a user