Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
This playbook summarizes data for Network Session Essentials and lands it into custom tables.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Network Session Essentials |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
NetworkCustomAnalytics_CL |
? | ✓ | ? |
NetworkCustomAnalytics_country_CL |
? | ✓ | ? |
NetworkCustomAnalytics_ip_CL |
? | ✓ | ? |
NetworkCustomAnalytics_protocol_CL 🔶 |
? | ✓ | ? |
NetworkCustomAnalytics_rule_CL |
? | ✓ | ? |
NetworkCustomAnalytics_sourceInfo_CL |
? | ✓ | ? |
NetworkCustomAnalytics_source_port_CL |
? | ✓ | ? |
NetworkCustomAnalytics_threat_CL |
? | ✓ | ? |
NetworkCustomAnalytics_threat_ioc_CL |
? | ✓ | ? |
📄 Source: SummarizeData_NSE/readme.md
This logic app helps to summarize Network session data into custom tables. This would incur additional cost.
## Summary To ensure good performance of Network Session Essentials solution, summarization capability can be used. This would create various custom tables containing analytics based on different parameters of ASIM Network Session Schema.
Deploy the playbook by clicking on "Deploy to Azure" button. This will take you to deploying an ARM Template wizard.
Fill in the required parameter:
Once deployment is complete, you will need to authorize each connection. 1. Click the Azure Monitor Logs 2. Click edit API connection 3. Click Authorize 4. Sign in 5. Click Save 6. Click the Azure Log Analytics Data Collector 7. Click edit API connection 8. Add value for workspace id and key which is associated with the Sentinel instance 9. Click Save
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊