Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
The 'SummarizeWebSessionData' Playbook helps with summarizing the Web Session logs and ingesting them into custom tables for persistence. Although enabling the summarization playbook for the Web Session solution is totally optional, we highly recommend enabling it for a better user experience in environments with high EPS (events per second) data ingestion. After installing the solution, it will be deployed under Playbook Templates in the Automation blade of Microsoft Sentinel. It can be configu
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Web Session Essentials |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
WebSession_Summarized_DstIPV1_CL |
? | ✓ | ? |
WebSession_Summarized_SrcIPV1_CL |
? | ✓ | ? |
WebSession_Summarized_SrcInfoV1_CL |
? | ✓ | ? |
WebSession_Summarized_ThreatInfoV1_CL |
? | ✓ | ? |
This playbook uses 2 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuremonitorlogs |
Managed | 1 | 4 |
http |
Built-in | 0 | 4 |
azuremonitorlogs (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Run_query_and_list_results_DstIP | post | /queryData |
— |
| Run_query_and_list_results_SourceInfo | post | /queryData |
— |
| Run_query_and_list_results_SrcIP | post | /queryData |
— |
| Run_query_and_list_results_ThreatInfo | post | /queryData |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Send_Data_DstIP | POST | @concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_DstIPV1', '?api-version=2023-01-01') |
— |
| Send_Data_SourceInfo | POST | @concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_SrcInfoV1', '?api-version=2023-01-01') |
— |
| Send_Data_SrcIP | POST | @concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_SrcIPV1', '?api-version=2023-01-01') |
— |
| Send_Data | POST | @concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_ThreatInfoV1', '?api-version=2023-01-01') |
— |
This Logic App ingests summarized Web Session data into custom Log Analytics tables by using the Logs Ingestion API. Enabling this playbook incurs additional cost.
The playbook improves Web Session Essentials solution performance by creating four tables containing analytics based on the ASIM Web Session schema:
WebSession_Summarized_SrcInfoV1_CLWebSession_Summarized_SrcIPV1_CLWebSession_Summarized_DstIPV1_CLWebSession_Summarized_ThreatInfoV1_CLThe V1 table names avoid conflicts with existing classic tables. The playbook uses a data collection endpoint (DCE), data collection rule (DCR), and its managed identity to ingest summarized data.
SummarizeWebSessionData-logingestion.The deployment creates the DCE, DCR, V1 custom tables, and grants the playbook managed identity the Monitoring Metrics Publisher role on the DCR.
Authorize the Azure Monitor Logs API connection if prompted:
The Logs Ingestion API uses the playbook's managed identity. No Azure Log Analytics Data Collector connection or workspace key is required.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊