Solution: AristaAwakeSecurity
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | Arista - Awake Security |
| Support Tier | Partner |
| Support Link | https://awakesecurity.com/ |
| Categories | domains |
| Version | 3.0.1 |
| Author | Arista Networks - support-security@arista.com |
| First Published | 2021-10-18 |
| Solution Folder | AristaAwakeSecurity |
| Marketplace | Azure Marketplace · Popularity: ⚪ Very Low (0%) |
| Pre-requisites | Common Event Format |
The Awake Security Arista Networks solution for Microsoft Sentinel enable users to send detection model matches from the Awake Security Platform to Microsoft Sentinel.
This solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.
NOTE: Microsoft recommends installation of CEF via AMA Connector. Legacy connector uses the Log Analytics agent which were deprecated on Aug 31, 2024. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost more details.
This solution depends on 1 other solution(s):
| Solution |
|---|
| Common Event Format |
This solution has 1 discovered data connector(s)⚠️ (not in Solution definition):
Connectors from dependency solutions:
🔍 Discovered: This item was discovered by scanning the solution folder but is not listed in the Solution JSON file.
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
CommonSecurityLog |
Common Event Format (CEF) (dependency), Common Event Format (CEF) via AMA (dependency), [Deprecated] Awake Security via Legacy Agent | Analytics, Workbooks |
This solution includes 4 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 3 |
| Workbooks | 1 |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Awake Security - High Match Counts By Device | Medium | - | CommonSecurityLog |
| Awake Security - High Severity Matches By Device | Medium | - | CommonSecurityLog |
| Awake Security - Model With Multiple Destinations | Medium | - | CommonSecurityLog |
| Name | Tables Used |
|---|---|
| AristaAwakeSecurityWorkbook | CommonSecurityLog |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.1 | 03-01-2025 | Removed Deprecated Data connector |
| 3.0.0 | 09-07-2024 | Deprecating data connectors. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊