Summarize Web Session Data using Log Ingestion API

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


The 'SummarizeWebSessionData' Playbook helps with summarizing the Web Session logs and ingesting them into custom tables for persistence. Although enabling the summarization playbook for the Web Session solution is totally optional, we highly recommend enabling it for a better user experience in environments with high EPS (events per second) data ingestion. After installing the solution, it will be deployed under Playbook Templates in the Automation blade of Microsoft Sentinel. It can be configu

Attribute Value
Type Playbook
Solution Web Session Essentials
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
WebSession_Summarized_DstIPV1_CL ? ✓ ?
WebSession_Summarized_SrcIPV1_CL ? ✓ ?
WebSession_Summarized_SrcInfoV1_CL ? ✓ ?
WebSession_Summarized_ThreatInfoV1_CL ? ✓ ?

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuremonitorlogs Managed 1 4
http Built-in 0 4
Action parameters (URLs, paths, function IDs)

azuremonitorlogs (Managed)

Action Method Endpoint Other
Run_query_and_list_results_DstIP post /queryData —
Run_query_and_list_results_SourceInfo post /queryData —
Run_query_and_list_results_SrcIP post /queryData —
Run_query_and_list_results_ThreatInfo post /queryData —

http (Built-in)

Action Method Endpoint Other
Send_Data_DstIP POST @concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_DstIPV1', '?api-version=2023-01-01') —
Send_Data_SourceInfo POST @concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_SrcInfoV1', '?api-version=2023-01-01') —
Send_Data_SrcIP POST @concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_SrcIPV1', '?api-version=2023-01-01') —
Send_Data POST @concat(parameters('ingestionEndpoint'), 'Custom-WebSession_Summarized_ThreatInfoV1', '?api-version=2023-01-01') —

Additional Documentation

📄 Source: SummarizeWebSessionData_logingestion/readme.md

Web Session Essentials Summarization Capability

This Logic App ingests summarized Web Session data into custom Log Analytics tables by using the Logs Ingestion API. Enabling this playbook incurs additional cost.

Summary

The playbook improves Web Session Essentials solution performance by creating four tables containing analytics based on the ASIM Web Session schema:

The V1 table names avoid conflicts with existing classic tables. The playbook uses a data collection endpoint (DCE), data collection rule (DCR), and its managed identity to ingest summarized data.

Deployment Instructions

  1. Deploy the playbook by selecting the applicable button:

Deploy to Azure Deploy to Azure Gov

  1. Deploy the playbook to a resource group in the same Azure region as the Log Analytics workspace.
  2. Provide the required parameters:
    • Playbook Name: The default is SummarizeWebSessionData-logingestion.
    • Log Analytics Name: The Log Analytics workspace that contains the Web Session data.
    • Resource Group Name and Subscription ID: The workspace resource group and subscription.

The deployment creates the DCE, DCR, V1 custom tables, and grants the playbook managed identity the Monitoring Metrics Publisher role on the DCR.

Post-Deployment Instructions

Authorize the Azure Monitor Logs API connection if prompted:

  1. Open the Azure Monitor Logs API connection.
  2. Select Edit API connection.
  3. Select Authorize, sign in, and then save the connection.

The Logs Ingestion API uses the playbook's managed identity. No Azure Log Analytics Data Collector connection or workspace key is required.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to Web Session Essentials