⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | VMware by Broadcom |
| Support Tier | Partner |
| Support Link | https://developer.vmware.com/ |
| Categories | domains |
| Version | 1.0.0 |
| Author | VMware by Broadcom |
| First Published | 2023-12-31 |
| Solution Folder | VMware SD-WAN and SASE |
The VMware SASE solution provides the capability to ingest telemetry and event data from your VMware SD-WAN fabric and Cloud Web Security service into Microsoft Sentinel through Syslog and the Orchestrator REST API.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Azure Monitor Log Ingestion API
c. Azure Monitor Agent for Syslog collection
This solution provides 1 data connector(s):
This solution uses 7 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
Heartbeat |
- | Workbooks |
Syslog |
- | Analytics, Workbooks |
VMware_CWS_DLPLogs_CL |
VMware SD-WAN and SASE Connector | Analytics |
VMware_CWS_Health_CL |
VMware SD-WAN and SASE Connector | Workbooks |
VMware_CWS_Weblogs_CL |
VMware SD-WAN and SASE Connector | Analytics, Workbooks |
VMware_SDWAN_FirewallLogs_CL |
- | Analytics |
VMware_VECO_EventLogs_CL |
VMware SD-WAN and SASE Connector | Analytics, Workbooks |
This solution includes 16 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 14 |
| Hunting Queries | 1 |
| Workbooks | 1 |
| Name | Tactics | Tables Used |
|---|---|---|
| VMware Edge Cloud Orchestrator - High number of login failures from a source IP address | CredentialAccess, InitialAccess | - |
| Name | Tables Used |
|---|---|
| VMwareSASESOCDashboard | HeartbeatSyslogVMware_CWS_Health_CLVMware_CWS_Weblogs_CLVMware_VECO_EventLogs_CL |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊