Summarize Data for Network Session Essentials using log ingestion API

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This playbook summarizes data for Network Session Essentials and lands it into custom tables.

Attribute Value
Type Playbook
Solution Network Session Essentials
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
NetworkCustomAnalyticsV1_CL ? ✓ ?
NetworkCustomAnalytics_countryV1_CL ? ✓ ?
NetworkCustomAnalytics_ipV1_CL ? ✓ ?
NetworkCustomAnalytics_protocolV1_CL ? ✓ ?
NetworkCustomAnalytics_ruleV1_CL ? ✓ ?
NetworkCustomAnalytics_sourceInfoV1_CL ? ✓ ?
NetworkCustomAnalytics_source_portV1_CL ? ✓ ?
NetworkCustomAnalytics_threatV1_CL ? ✓ ?
NetworkCustomAnalytics_threat_iocV1_CL ? ✓ ?

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuremonitorlogs Managed 1 9
http Built-in 0 9
Action parameters (URLs, paths, function IDs)

azuremonitorlogs (Managed)

Action Method Endpoint Other
Run_query_and_list_results_-_IP post /queryData —
Run_query_and_list_results_-_Port post /queryData —
Run_query_and_list_results_-_GeoCountry post /queryData —
Run_query_and_list_results_-_Overall post /queryData —
Run_query_and_list_results_-_Protocol post /queryData —
Run_query_and_list_results_-_Rules post /queryData —
Run_query_and_list_results_-_SourceInfo post /queryData —
Run_query_and_list_results_-_Threat post /queryData —
Run_query_and_list_results_-_Threat_IOC post /queryData —

http (Built-in)

Action Method Endpoint Other
Send_Data_-_IP POST @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_ip', '?api-version=2023-01-01') —
Send_Data_-_Port POST @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_source_port', '?api-version=2023-01-01') —
Send_Data_-_GeoCountry POST @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_country', '?api-version=2023-01-01') —
Send_Data_-_Overall POST @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics', '?api-version=2023-01-01') —
Send_Data_-_Protocol POST @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_protocol', '?api-version=2023-01-01') —
Send_Data_-_SourceInfo POST @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_sourceInfo', '?api-version=2023-01-01') —
Send_Data_-_Threat POST @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_threat', '?api-version=2023-01-01') —
Send_Data_-_Threat_IOC POST @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_threat_ioc', '?api-version=2023-01-01') —
Send_Data_-_Rule POST @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_rule', '?api-version=2023-01-01') —

Additional Documentation

📄 Source: SummarizeData_NSE_Logingestionapi/readme.md

Network Session Essentials Solution Summarization Capability

This Logic App summarizes Network Session data into custom Log Analytics tables by using the Logs Ingestion API. This capability incurs additional cost.

Summary

The playbook improves Network Session Essentials workbook and query performance by creating summarized data for key ASIM Network Session dimensions. It uses a data collection endpoint (DCE), data collection rule (DCR), and the playbook's managed identity to ingest data into V1 custom tables.

V1 custom tables

The playbook creates the following tables. Use these V1 names in custom queries; existing non-V1 tables are not modified.

Table Summarized dimensions
NetworkCustomAnalytics_ipV1_CL Source IP, destination IP, network direction, and device action.
NetworkCustomAnalytics_source_portV1_CL Source port, network direction, and device action.
NetworkCustomAnalytics_countryV1_CL Source country, destination country, device action, and network direction.
NetworkCustomAnalyticsV1_CL Overall event result, network direction, device action, and event severity.
NetworkCustomAnalytics_protocolV1_CL Network protocol, destination port, destination application, network direction, and device action.
NetworkCustomAnalytics_sourceInfoV1_CL Event product and device hostname.
NetworkCustomAnalytics_threatV1_CL Threat, threat category, event severity, and device action.
NetworkCustomAnalytics_threat_iocV1_CL Source and destination IP addresses and hostnames.
NetworkCustomAnalytics_ruleV1_CL Rule, network direction, and device action.

Each table also includes TimeGenerated, EventTime, and count_ for its aggregation window and event count.

Deployment Instructions

  1. Deploy the playbook by selecting the applicable button:

Deploy to Azure Deploy to Azure Gov

  1. Deploy the playbook to a resource group in the same Azure region as the Log Analytics workspace.
  2. Provide the required parameters:
    • Playbook Name: The default is SummarizeData_NSE_Logingestionapi.
    • Log Analytics Name: The Log Analytics workspace that contains the Network Session data.
    • Resource Group Name and Subscription ID: The workspace resource group and subscription.

The deployment creates the DCE, DCR, required custom tables, and grants the playbook managed identity the Monitoring Metrics Publisher role on the DCR.

Post-Deployment Instructions

Authorize the Azure Monitor Logs API connection if prompted:

  1. Open the Azure Monitor Logs API connection.
  2. Select Edit API connection.
  3. Select Authorize, sign in, and then save the connection.

The Logs Ingestion API uses the playbook's managed identity. No Azure Log Analytics Data Collector connection or workspace key is required.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to Network Session Essentials