Cisco Catalyst SD-WAN Sentinel Application

Solution: Cisco SD-WAN

Cisco SD-WAN Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher Cisco Systems
Support Tier Partner
Support Link https://globalcontacts.cloudapps.cisco.com/contacts/contactDetails/en_US/c1o1-c2o2-c3o8
Categories domains
Version 2.0.0
Author Cisco Systems - support@cisco.com
First Published 2023-06-01
Last Updated 2024-06-01
Solution Folder Cisco SD-WAN
Marketplace Azure Marketplace · Popularity: 🔵 Medium (53%)

The Cisco SD-WAN solution for Microsoft Sentinel enables you to ingest Syslog and Netflow logs into Microsoft Sentinel, providing insight into network threats and vulnerabilities.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Agent-based log collection (Syslog)

Contents

Data Connectors

This solution provides 1 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 2 table(s):

Table Used By Connectors Used By Content
CiscoSDWANNetflow_CL 🔶 Cisco Software Defined WAN Analytics, Workbooks
Syslog Cisco Software Defined WAN Analytics, Workbooks

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 12 content item(s) (8 in solution, 4 discovered 🔍):

Content Type Total In Solution Discovered
Analytic Rules 4 4 -
Parsers 4 0 4
Playbooks 3 3 -
Workbooks 1 1 -

Analytic Rules

Name Severity Tactics Tables Used
Cisco SDWAN - IPS Event Threshold High InitialAccess Syslog
Cisco SDWAN - Intrusion Events High InitialAccess Syslog
Cisco SDWAN - Maleware Events High ResourceDevelopment CiscoSDWANNetflow_CL
Syslog
Cisco SDWAN - Monitor Critical IPs High CommandAndControl CiscoSDWANNetflow_CL
Syslog

Workbooks

Name Tables Used
CiscoSDWAN CiscoSDWANNetflow_CL
Syslog

Playbooks

Name Description Tables Used
CiscoSDWANIntrusionLogicAPP This playbook provides an end-to-end example of adding a comment in the generated incident. -
CiscoSDWANLogicAPP This playbook provides an end-to-end example of sending an email, posting a message to the Microsoft... -
CiscoSDWANReport This playbook provides an end-to-end example of sending an email for suspicious activity found in th... -

Parsers

Name Description Tables Used
CiscoSDWANNetflow ⚠️ - CiscoSDWANNetflow_CL (read)
CiscoSyslogFW6LogSummary ⚠️ - Syslog (read)
CiscoSyslogUTD ⚠️ - Syslog (read)
MapNetflowUsername ⚠️ - -

⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index