Skip to content

Commit

Permalink
Merge pull request #11645 from idoscapa/idoscapa/mdiot_analyticrules_…
Browse files Browse the repository at this point in the history
…entities

Idoscapa/mdiot analyticrules entities
  • Loading branch information
v-prasadboke authored Jan 9, 2025
2 parents ad992c0 + 5d1d41e commit cb54692
Show file tree
Hide file tree
Showing 15 changed files with 45 additions and 135 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -48,14 +48,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -79,5 +73,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -48,14 +48,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -79,5 +73,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -48,14 +48,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -79,5 +73,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -49,14 +49,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -80,5 +74,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,8 @@ query: |
AlertManagementUri,
Techniques
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: SourceDeviceAddress
- entityType: IP
fieldMappings:
- identifier: Address
columnName: DestDeviceAddress
sentinelEntitiesMappings:
- columnName: Entities
eventGroupingSettings:
aggregationKind: AlertPerResult
customDetails:
Expand All @@ -78,5 +72,5 @@ alertDetailsOverride:
value: ProductComponentName
- alertProperty: AlertLink
value: AlertLink
version: 1.0.2
version: 1.0.3
kind: Scheduled

0 comments on commit cb54692

Please sign in to comment.