Armorblox

Armorblox Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher Armorblox
Support Tier Partner
Support Link https://www.armorblox.com/contact/
Categories domains
Version 3.0.1
Author Armorblox - support@armorblox.com
First Published 2021-10-18
Solution Folder Armorblox

The Armorblox solution provides the capability to ingest incidents from your Armorblox instance into Microsoft Sentinel through the REST API.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Azure Monitor HTTP Data Collector API

b. Azure Functions

Contents

Data Connectors

This solution provides 1 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
Armorblox_CL 🔶 Armorblox Analytics, Workbooks

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 3 content item(s):

Content Type Count
Analytic Rules 1
Workbooks 1
Playbooks 1

Analytic Rules

Name Severity Tactics Tables Used
Armorblox Needs Review Alert Medium - Armorblox_CL

Workbooks

Name Tables Used
ArmorbloxOverview Armorblox_CL

Playbooks

Name Description Tables Used
Needs-Review-Incident-Email-Notification This playbook will send an email notification when a new incident is created in Microsoft Sentinel. -

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.1 11-09-2024 Updated the python runtime version to 3.11
3.0.0 23-11-2023 Added entity mapping in Analytical Rule [Armorblox Needs Review Alert]

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index