Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook summarizes data for Network Session Essentials and lands it into custom tables.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Network Session Essentials |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
NetworkCustomAnalyticsV1_CL |
? | ✓ | ? |
NetworkCustomAnalytics_countryV1_CL |
? | ✓ | ? |
NetworkCustomAnalytics_ipV1_CL |
? | ✓ | ? |
NetworkCustomAnalytics_protocolV1_CL |
? | ✓ | ? |
NetworkCustomAnalytics_ruleV1_CL |
? | ✓ | ? |
NetworkCustomAnalytics_sourceInfoV1_CL |
? | ✓ | ? |
NetworkCustomAnalytics_source_portV1_CL |
? | ✓ | ? |
NetworkCustomAnalytics_threatV1_CL |
? | ✓ | ? |
NetworkCustomAnalytics_threat_iocV1_CL |
? | ✓ | ? |
This playbook uses 2 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuremonitorlogs |
Managed | 1 | 9 |
http |
Built-in | 0 | 9 |
azuremonitorlogs (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Run_query_and_list_results_-_IP | post | /queryData |
— |
| Run_query_and_list_results_-_Port | post | /queryData |
— |
| Run_query_and_list_results_-_GeoCountry | post | /queryData |
— |
| Run_query_and_list_results_-_Overall | post | /queryData |
— |
| Run_query_and_list_results_-_Protocol | post | /queryData |
— |
| Run_query_and_list_results_-_Rules | post | /queryData |
— |
| Run_query_and_list_results_-_SourceInfo | post | /queryData |
— |
| Run_query_and_list_results_-_Threat | post | /queryData |
— |
| Run_query_and_list_results_-_Threat_IOC | post | /queryData |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Send_Data_-_IP | POST | @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_ip', '?api-version=2023-01-01') |
— |
| Send_Data_-_Port | POST | @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_source_port', '?api-version=2023-01-01') |
— |
| Send_Data_-_GeoCountry | POST | @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_country', '?api-version=2023-01-01') |
— |
| Send_Data_-_Overall | POST | @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics', '?api-version=2023-01-01') |
— |
| Send_Data_-_Protocol | POST | @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_protocol', '?api-version=2023-01-01') |
— |
| Send_Data_-_SourceInfo | POST | @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_sourceInfo', '?api-version=2023-01-01') |
— |
| Send_Data_-_Threat | POST | @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_threat', '?api-version=2023-01-01') |
— |
| Send_Data_-_Threat_IOC | POST | @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_threat_ioc', '?api-version=2023-01-01') |
— |
| Send_Data_-_Rule | POST | @concat(parameters('ingestionEndpoint'), 'Custom-NetworkCustomAnalytics_rule', '?api-version=2023-01-01') |
— |
This Logic App summarizes Network Session data into custom Log Analytics tables by using the Logs Ingestion API. This capability incurs additional cost.
The playbook improves Network Session Essentials workbook and query performance by creating summarized data for key ASIM Network Session dimensions. It uses a data collection endpoint (DCE), data collection rule (DCR), and the playbook's managed identity to ingest data into V1 custom tables.
The playbook creates the following tables. Use these V1 names in custom queries; existing non-V1 tables are not modified.
| Table | Summarized dimensions |
|---|---|
NetworkCustomAnalytics_ipV1_CL |
Source IP, destination IP, network direction, and device action. |
NetworkCustomAnalytics_source_portV1_CL |
Source port, network direction, and device action. |
NetworkCustomAnalytics_countryV1_CL |
Source country, destination country, device action, and network direction. |
NetworkCustomAnalyticsV1_CL |
Overall event result, network direction, device action, and event severity. |
NetworkCustomAnalytics_protocolV1_CL |
Network protocol, destination port, destination application, network direction, and device action. |
NetworkCustomAnalytics_sourceInfoV1_CL |
Event product and device hostname. |
NetworkCustomAnalytics_threatV1_CL |
Threat, threat category, event severity, and device action. |
NetworkCustomAnalytics_threat_iocV1_CL |
Source and destination IP addresses and hostnames. |
NetworkCustomAnalytics_ruleV1_CL |
Rule, network direction, and device action. |
Each table also includes TimeGenerated, EventTime, and count_ for its aggregation window and event count.
SummarizeData_NSE_Logingestionapi.The deployment creates the DCE, DCR, required custom tables, and grants the playbook managed identity the Monitoring Metrics Publisher role on the DCR.
Authorize the Azure Monitor Logs API connection if prompted:
The Logs Ingestion API uses the playbook's managed identity. No Azure Log Analytics Data Collector connection or workspace key is required.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊