diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 1a27e7782d6..1e55a7b73e5 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -24,6 +24,7 @@ /packages/azure_application_insights @elastic/obs-cloud-monitoring /packages/azure_billing @elastic/obs-cloud-monitoring /packages/azure @elastic/obs-cloud-monitoring +/packages/azure_frontdoor @elastic/security-external-integrations /packages/azure_metrics @elastic/obs-cloud-monitoring /packages/barracuda @elastic/security-external-integrations /packages/barracuda_cloudgen_firewall @elastic/security-external-integrations diff --git a/packages/azure_frontdoor/_dev/build/build.yml b/packages/azure_frontdoor/_dev/build/build.yml new file mode 100644 index 00000000000..ca551c032a8 --- /dev/null +++ b/packages/azure_frontdoor/_dev/build/build.yml @@ -0,0 +1,3 @@ +dependencies: + ecs: + reference: git@8.6 diff --git a/packages/azure_frontdoor/_dev/build/docs/README.md b/packages/azure_frontdoor/_dev/build/docs/README.md new file mode 100644 index 00000000000..784eb26ac85 --- /dev/null +++ b/packages/azure_frontdoor/_dev/build/docs/README.md @@ -0,0 +1,61 @@ +# Azure Frontdoor Logs Integration + +The azure frontdoor logs integration retrieves different types of log data from AFD. +Azure Front Door provides different logging to help you track, monitor, and debug your Front Door. + +- Access logs have detailed information about every request that AFD receives and help you analyze and monitor access patterns, and debug issues. +- Activity logs provide visibility into the operations done on Azure resources. +- Health Probe logs provides the logs for every failed probe to your origin. +- Web Application Firewall (WAF) logs provide detailed information of requests that gets logged through either detection or prevention mode of an Azure Front Door endpoint. A custom domain that gets configured with WAF can also be viewed through these logs. + +## Data streams + +This integration collects two types of data streams: + +- access log +- waf logs + +## Requirements + +### Credentials + +`eventhub` : +_string_ +Is the fully managed, real-time data ingestion service. + +`consumer_group` : +_string_ +The publish/subscribe mechanism of Event Hubs is enabled through consumer groups. A consumer group is a view (state, position, or offset) of an entire event hub. Consumer groups enable multiple consuming applications to each have a separate view of the event stream, and to read the stream independently at their own pace and with their own offsets. +Default value: `$Default` + +`connection_string` : +_string_ +The connection string required to communicate with Event Hubs, steps here https://docs.microsoft.com/en-us/azure/event-hubs/event-hubs-get-connection-string. + +A Blob Storage account is required in order to store/retrieve/update the offset or state of the eventhub messages. This means that after stopping the filebeat azure module it can start back up at the spot that it stopped processing messages. + +`storage_account` : +_string_ +The name of the storage account the state/offsets will be stored and updated. + +`storage_account_key` : +_string_ +The storage account key, this key will be used to authorize access to data in your storage account. + +`resource_manager_endpoint` : +_string_ +Optional, by default we are using the azure public environment, to override, users can provide a specific resource manager endpoint in order to use a different azure environment. +Ex: +https://management.chinacloudapi.cn/ for azure ChinaCloud +https://management.microsoftazure.de/ for azure GermanCloud +https://management.azure.com/ for azure PublicCloud +https://management.usgovcloudapi.net/ for azure USGovernmentCloud +Users can also use this in case of a Hybrid Cloud model, where one may define their own endpoints. + +## Acceess Logs + +{{fields "access"}} + +## WAF Logs + +{{fields "waf"}} diff --git a/packages/azure_frontdoor/changelog.yml b/packages/azure_frontdoor/changelog.yml new file mode 100644 index 00000000000..1dd4bbcbdcc --- /dev/null +++ b/packages/azure_frontdoor/changelog.yml @@ -0,0 +1,6 @@ +# newer versions go on top +- version: "0.0.1" + changes: + - description: Initial draft of the package + type: enhancement + link: https://github.com/elastic/integrations/pull/2497 diff --git a/packages/azure_frontdoor/data_stream/access/_dev/test/pipeline/test-common-config.yml b/packages/azure_frontdoor/data_stream/access/_dev/test/pipeline/test-common-config.yml new file mode 100644 index 00000000000..e11f3ae9932 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/_dev/test/pipeline/test-common-config.yml @@ -0,0 +1,6 @@ +dynamic_fields: + event.ingested: ".*" +fields: + tags: + - preserve_original_event + - azure-frontdoor-access diff --git a/packages/azure_frontdoor/data_stream/access/_dev/test/pipeline/test-fdaccess.log b/packages/azure_frontdoor/data_stream/access/_dev/test/pipeline/test-fdaccess.log new file mode 100644 index 00000000000..d2235f2240a --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/_dev/test/pipeline/test-fdaccess.log @@ -0,0 +1,4 @@ +{"category":"FrontdoorAccessLog","operationName":"Microsoft.Network/FrontDoor/AccessLog/Write","properties":{"ErrorInfo":"NoError","backendHostname":"samplev6erp.azurewebsites.net:443","cacheStatus":"CONFIG_NOCACHE","clientIp":"89.160.20.128","clientPort":"50382","httpMethod":"POST","httpStatusCode":"200","httpStatusDetails":"200","httpVersion":"2.0.0.0","isReceivedFromClient":true,"pop":"SIN","requestBytes":"2545","requestProtocol":"HTTPS","requestUri":"https://erp.testcloud.com:443/StockSetup/GetStockListByCir","responseBytes":"1205","routingRuleName":"erp","rulesEngineMatchNames":[],"securityProtocol":"TLS 1.2","socketIp":"89.160.20.128","timeTaken":"0.384","timeToFirstByte":"0.384","trackingReference":"0k1y5YQAAAAAWd0Uc6UcnR7WN8uo2prYZU0lOMzBFREdFMDIxNwBkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc=","userAgent":"Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36"},"resourceId":"/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD","time":"2021-12-15T03:10:11.6479719Z"} +{"category":"FrontdoorAccessLog","operationName":"Microsoft.Network/FrontDoor/AccessLog/Write","properties":{"ErrorInfo":"NoError","backendHostname":"samplev6erp.azurewebsites.net:443","cacheStatus":"CONFIG_NOCACHE","clientIp":"175.16.199.0","clientPort":"6610","httpMethod":"GET","httpStatusCode":"200","httpStatusDetails":"200","httpVersion":"2.0.0.0","isReceivedFromClient":true,"pop":"SIN","requestBytes":"1984","requestProtocol":"HTTPS","requestUri":"https://erp.testcloud.com:443/saleInvoice/readBySyskeySIByRoleAllowed/2112140619239361392","responseBytes":"2308","routingRuleName":"erp","rulesEngineMatchNames":[],"securityProtocol":"TLS 1.2","socketIp":"175.16.199.0","timeTaken":"0.122","timeToFirstByte":"0.122","trackingReference":"0lWK5YQAAAAD89Q/jewlnT7dWvZNIh72LU0lOMzBFREdFMDIxNwBkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc=","userAgent":"Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36"},"resourceId":"/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD","time":"2021-12-15T03:35:49.9266300Z"} +{"category":"FrontdoorAccessLog","operationName":"Microsoft.Network/FrontDoor/AccessLog/Write","properties":{"ErrorInfo":"NoError","backendHostname":"samplev6erp.azurewebsites.net:443","cacheStatus":"CONFIG_NOCACHE","clientIp":"175.16.199.0","clientPort":"6610","httpMethod":"GET","httpStatusCode":"200","httpStatusDetails":"200","httpVersion":"2.0.0.0","isReceivedFromClient":true,"pop":"SIN","requestBytes":"1971","requestProtocol":"HTTPS","requestUri":"https://erp.testcloud.com:443/Customer/searchContactList/2107050813256062892","responseBytes":"637","routingRuleName":"erp","rulesEngineMatchNames":[],"securityProtocol":"TLS 1.2","socketIp":"175.16.199.0","timeTaken":"0.064","timeToFirstByte":"0.064","trackingReference":"0lWK5YQAAAAAnKnstK4rwSovl+unjuKhoU0lOMzBFREdFMDIxNwBkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc=","userAgent":"Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36"},"resourceId":"/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD","time":"2021-12-15T03:35:50.0584922Z"} +{''"records"'': [{"time":"2021-02-02T07:15:37.3640748Z","resourceId":"/SUBSCRIPTIONS/saDFEEQW-JESSIE","category":"FrontdoorAccessLog"}]} \ No newline at end of file diff --git a/packages/azure_frontdoor/data_stream/access/_dev/test/pipeline/test-fdaccess.log-expected.json b/packages/azure_frontdoor/data_stream/access/_dev/test/pipeline/test-fdaccess.log-expected.json new file mode 100644 index 00000000000..9bbc286649d --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/_dev/test/pipeline/test-fdaccess.log-expected.json @@ -0,0 +1,290 @@ +{ + "expected": [ + { + "@timestamp": "2021-12-15T03:10:11.647Z", + "azure": { + "frontdoor": { + "access": { + "backend_hostname": "samplev6erp.azurewebsites.net:443", + "cache_status": "CONFIG_NOCACHE", + "error_info": "NoError", + "is_received_from_client": true, + "pop": "SIN", + "routing_rule_name": "erp", + "rules_engine_match_names": [], + "time_taken": "0.384", + "time_to_first_byte": "0.384" + }, + "category": "FrontdoorAccessLog", + "operation_name": "Microsoft.Network/FrontDoor/AccessLog/Write", + "resource_id": "/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD", + "tracking_reference": "0k1y5YQAAAAAWd0Uc6UcnR7WN8uo2prYZU0lOMzBFREdFMDIxNwBkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc=" + } + }, + "client": { + "address": "89.160.20.128", + "ip": "89.160.20.128", + "port": 50382 + }, + "cloud": { + "provider": "azure" + }, + "ecs": { + "version": "8.6.0" + }, + "event": { + "category": [ + "network" + ], + "type": [ + "connection" + ] + }, + "http": { + "request": { + "bytes": 2545, + "method": "POST" + }, + "response": { + "bytes": 1205, + "status_code": 200 + }, + "version": "2.0.0.0" + }, + "network": { + "protocol": "HTTPS" + }, + "source": { + "as": { + "number": 29518, + "organization": { + "name": "Bredband2 AB" + } + }, + "geo": { + "city_name": "Linköping", + "continent_name": "Europe", + "country_iso_code": "SE", + "country_name": "Sweden", + "location": { + "lat": 58.4167, + "lon": 15.6167 + }, + "region_iso_code": "SE-E", + "region_name": "Östergötland County" + } + }, + "tags": [ + "preserve_original_event", + "azure-frontdoor-access" + ], + "tls": { + "version": "1.2", + "version_protocol": "TLS" + }, + "url": { + "original": "https://erp.testcloud.com:443/StockSetup/GetStockListByCir" + }, + "user_agent": { + "device": { + "name": "Other" + }, + "name": "Chrome", + "original": "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36", + "os": { + "full": "Windows 7", + "name": "Windows", + "version": "7" + }, + "version": "96.0.4664.93" + } + }, + { + "@timestamp": "2021-12-15T03:35:49.926Z", + "azure": { + "frontdoor": { + "access": { + "backend_hostname": "samplev6erp.azurewebsites.net:443", + "cache_status": "CONFIG_NOCACHE", + "error_info": "NoError", + "is_received_from_client": true, + "pop": "SIN", + "routing_rule_name": "erp", + "rules_engine_match_names": [], + "time_taken": "0.122", + "time_to_first_byte": "0.122" + }, + "category": "FrontdoorAccessLog", + "operation_name": "Microsoft.Network/FrontDoor/AccessLog/Write", + "resource_id": "/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD", + "tracking_reference": "0lWK5YQAAAAD89Q/jewlnT7dWvZNIh72LU0lOMzBFREdFMDIxNwBkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc=" + } + }, + "client": { + "address": "175.16.199.0", + "ip": "175.16.199.0", + "port": 6610 + }, + "cloud": { + "provider": "azure" + }, + "ecs": { + "version": "8.6.0" + }, + "event": { + "category": [ + "network" + ], + "type": [ + "connection" + ] + }, + "http": { + "request": { + "bytes": 1984, + "method": "GET" + }, + "response": { + "bytes": 2308, + "status_code": 200 + }, + "version": "2.0.0.0" + }, + "network": { + "protocol": "HTTPS" + }, + "source": { + "geo": { + "city_name": "Changchun", + "continent_name": "Asia", + "country_iso_code": "CN", + "country_name": "China", + "location": { + "lat": 43.88, + "lon": 125.3228 + }, + "region_iso_code": "CN-22", + "region_name": "Jilin Sheng" + } + }, + "tags": [ + "preserve_original_event", + "azure-frontdoor-access" + ], + "tls": { + "version": "1.2", + "version_protocol": "TLS" + }, + "url": { + "original": "https://erp.testcloud.com:443/saleInvoice/readBySyskeySIByRoleAllowed/2112140619239361392" + }, + "user_agent": { + "device": { + "name": "Other" + }, + "name": "Chrome", + "original": "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36", + "os": { + "full": "Windows 7", + "name": "Windows", + "version": "7" + }, + "version": "96.0.4664.93" + } + }, + { + "@timestamp": "2021-12-15T03:35:50.058Z", + "azure": { + "frontdoor": { + "access": { + "backend_hostname": "samplev6erp.azurewebsites.net:443", + "cache_status": "CONFIG_NOCACHE", + "error_info": "NoError", + "is_received_from_client": true, + "pop": "SIN", + "routing_rule_name": "erp", + "rules_engine_match_names": [], + "time_taken": "0.064", + "time_to_first_byte": "0.064" + }, + "category": "FrontdoorAccessLog", + "operation_name": "Microsoft.Network/FrontDoor/AccessLog/Write", + "resource_id": "/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD", + "tracking_reference": "0lWK5YQAAAAAnKnstK4rwSovl+unjuKhoU0lOMzBFREdFMDIxNwBkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc=" + } + }, + "client": { + "address": "175.16.199.0", + "ip": "175.16.199.0", + "port": 6610 + }, + "cloud": { + "provider": "azure" + }, + "ecs": { + "version": "8.6.0" + }, + "event": { + "category": [ + "network" + ], + "type": [ + "connection" + ] + }, + "http": { + "request": { + "bytes": 1971, + "method": "GET" + }, + "response": { + "bytes": 637, + "status_code": 200 + }, + "version": "2.0.0.0" + }, + "network": { + "protocol": "HTTPS" + }, + "source": { + "geo": { + "city_name": "Changchun", + "continent_name": "Asia", + "country_iso_code": "CN", + "country_name": "China", + "location": { + "lat": 43.88, + "lon": 125.3228 + }, + "region_iso_code": "CN-22", + "region_name": "Jilin Sheng" + } + }, + "tags": [ + "preserve_original_event", + "azure-frontdoor-access" + ], + "tls": { + "version": "1.2", + "version_protocol": "TLS" + }, + "url": { + "original": "https://erp.testcloud.com:443/Customer/searchContactList/2107050813256062892" + }, + "user_agent": { + "device": { + "name": "Other" + }, + "name": "Chrome", + "original": "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36", + "os": { + "full": "Windows 7", + "name": "Windows", + "version": "7" + }, + "version": "96.0.4664.93" + } + }, + null + ] +} \ No newline at end of file diff --git a/packages/azure_frontdoor/data_stream/access/agent/stream/azure-eventhub.yml.hbs b/packages/azure_frontdoor/data_stream/access/agent/stream/azure-eventhub.yml.hbs new file mode 100644 index 00000000000..daf9c0503b0 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/agent/stream/azure-eventhub.yml.hbs @@ -0,0 +1,39 @@ +{{#if connection_string}} +connection_string: {{connection_string}} +{{/if}} +{{#if storage_account_container }} +storage_account_container: {{storage_account_container}} +{{else}} +{{#if eventhub}} +storage_account_container: filebeat-firewalllogs-{{eventhub}} +{{/if}} +{{/if}} +{{#if eventhub}} +eventhub: {{eventhub}} +{{/if}} +{{#if consumer_group}} +consumer_group: {{consumer_group}} +{{/if}} +{{#if storage_account}} +storage_account: {{storage_account}} +{{/if}} +{{#if storage_account_key}} +storage_account_key: {{storage_account_key}} +{{/if}} +{{#if resource_manager_endpoint}} +resource_manager_endpoint: {{resource_manager_endpoint}} +{{/if}} +tags: +{{#if preserve_original_event}} + - preserve_original_event +{{/if}} +{{#each tags as |tag|}} + - {{tag}} +{{/each}} +{{#contains "forwarded" tags}} +publisher_pipeline.disable_host: true +{{/contains}} +{{#if processors}} +processors: +{{processors}} +{{/if}} \ No newline at end of file diff --git a/packages/azure_frontdoor/data_stream/access/elasticsearch/ingest_pipeline/default.yml b/packages/azure_frontdoor/data_stream/access/elasticsearch/ingest_pipeline/default.yml new file mode 100644 index 00000000000..3b2a63bea27 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/elasticsearch/ingest_pipeline/default.yml @@ -0,0 +1,186 @@ +--- +description: Pipeline for processing azure frontdoor access logs +processors: + - set: + field: ecs.version + value: "8.6.0" + - set: + field: event.category + value: [network] + - set: + field: event.type + value: [connection] + - rename: + field: message + target_field: event.original + ignore_missing: true + - set: + field: cloud.provider + value: azure + - drop: + description: Drop if inavlid json + if: 'ctx.event?.original != null && ctx.event.original.contains(''"records"'')' + - json: + field: event.original + target_field: azure.frontdoor.access + - rename: + field: azure.frontdoor.access.resourceId + target_field: azure.frontdoor.resource_id + ignore_missing: true + - rename: + field: azure.frontdoor.access.operationName + target_field: azure.frontdoor.operation_name + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.trackingReference + target_field: azure.frontdoor.tracking_reference + ignore_missing: true + - rename: + field: azure.frontdoor.access.category + target_field: azure.frontdoor.category + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.clientIp + target_field: client.ip + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.clientPort + target_field: client.port + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.requestBytes + target_field: http.request.bytes + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.socketIp + target_field: client.address + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.ErrorInfo + target_field: azure.frontdoor.access.error_info + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.rulesEngineMatchNames + target_field: azure.frontdoor.access.rules_engine_match_names + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.cacheStatus + target_field: azure.frontdoor.access.cache_status + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.userAgent + target_field: user_agent.original + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.httpMethod + target_field: http.request.method + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.timeToFirstByte + target_field: azure.frontdoor.access.time_to_first_byte + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.pop + target_field: azure.frontdoor.access.pop + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.responseBytes + target_field: http.response.bytes + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.timeTaken + target_field: azure.frontdoor.access.time_taken + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.routingRuleName + target_field: azure.frontdoor.access.routing_rule_name + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.httpVersion + target_field: http.version + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.backendHostname + target_field: azure.frontdoor.access.backend_hostname + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.isReceivedFromClient + target_field: azure.frontdoor.access.is_received_from_client + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.requestProtocol + target_field: network.protocol + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.httpStatusCode + target_field: http.response.status_code + ignore_missing: true + - rename: + field: azure.frontdoor.access.properties.requestUri + target_field: url.original + ignore_missing: true + - convert: + field: client.port + type: long + ignore_missing: true + - convert: + field: http.request.bytes + type: long + ignore_missing: true + - convert: + field: http.response.bytes + type: long + ignore_missing: true + - convert: + field: http.response.status_code + type: long + ignore_missing: true + + - date: + field: azure.frontdoor.access.time + target_field: "@timestamp" + formats: + - ISO8601 + + - dissect: + field: azure.frontdoor.access.properties.securityProtocol + pattern: "%{tls.version_protocol} %{tls.version}" + ignore_missing: true + + - remove: + field: + - azure.frontdoor.access.properties.securityProtocol + - azure.frontdoor.access.properties.httpStatusDetails + - azure.frontdoor.access.time + - azure.frontdoor.access.properties + - event.original + ignore_missing: true + + - geoip: + field: client.ip + target_field: source.geo + ignore_missing: true + - geoip: + database_file: GeoLite2-ASN.mmdb + field: client.ip + target_field: source.as + properties: + - asn + - organization_name + ignore_missing: true + - rename: + field: source.as.asn + target_field: source.as.number + ignore_missing: true + - rename: + field: source.as.organization_name + target_field: source.as.organization.name + ignore_missing: true + - user_agent: + field: user_agent.original + ignore_missing: true + +on_failure: + - set: + field: error.message + value: "{{ _ingest.on_failure_message }}" diff --git a/packages/azure_frontdoor/data_stream/access/fields/agent.yml b/packages/azure_frontdoor/data_stream/access/fields/agent.yml new file mode 100644 index 00000000000..bca66ea4ae0 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/fields/agent.yml @@ -0,0 +1,62 @@ +- name: cloud.account.id + external: ecs +- name: cloud.availability_zone + external: ecs +- name: cloud.instance.id + external: ecs +- name: cloud.instance.name + external: ecs +- name: cloud.machine.type + external: ecs +- name: cloud.provider + external: ecs +- name: cloud.region + external: ecs +- name: cloud.project.id + external: ecs +- name: cloud.image.id + type: keyword + description: Image ID for the cloud instance. +- name: container.id + external: ecs +- name: container.image.name + external: ecs +- name: container.labels + external: ecs +- name: container.name + external: ecs +- name: host.architecture + external: ecs +- name: host.domain + external: ecs +- name: host.hostname + external: ecs +- name: host.id + external: ecs +- name: host.ip + external: ecs +- name: host.mac + external: ecs +- name: host.name + external: ecs +- name: host.os.family + external: ecs +- name: host.os.kernel + external: ecs +- name: host.os.name + external: ecs +- name: host.os.platform + external: ecs +- name: host.os.version + external: ecs +- name: host.type + external: ecs +- name: host.containerized + type: boolean + description: If the host is a container. +- name: host.os.build + type: keyword + description: OS build information. +- name: host.os.codename + type: keyword + description: OS codename, if any. diff --git a/packages/azure_frontdoor/data_stream/access/fields/base-fields.yml b/packages/azure_frontdoor/data_stream/access/fields/base-fields.yml new file mode 100644 index 00000000000..f245714ba9e --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/fields/base-fields.yml @@ -0,0 +1,21 @@ +- name: data_stream.type + type: constant_keyword + description: Data stream type. +- name: data_stream.dataset + type: constant_keyword + description: Data stream dataset. +- name: data_stream.namespace + type: constant_keyword + description: Data stream namespace. +- name: '@timestamp' + type: date + description: Event timestamp. +- name: input.type + type: keyword + description: Input type. +- name: log.offset + type: long + description: Log offset. +- name: log.file.path + type: keyword + description: Log file path. diff --git a/packages/azure_frontdoor/data_stream/access/fields/ecs.yml b/packages/azure_frontdoor/data_stream/access/fields/ecs.yml new file mode 100644 index 00000000000..34b91e4755f --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/fields/ecs.yml @@ -0,0 +1,144 @@ +- name: client.ip + external: ecs +- name: client.address + external: ecs +- name: client.port + external: ecs +- name: destination.address + external: ecs +- name: destination.as.number + external: ecs +- name: destination.as.organization.name + external: ecs +- name: destination.geo.city_name + external: ecs +- name: destination.geo.continent_name + external: ecs +- name: destination.geo.country_iso_code + external: ecs +- name: destination.geo.country_name + external: ecs +- name: destination.geo.location + external: ecs +- name: destination.geo.name + external: ecs +- name: destination.geo.region_iso_code + external: ecs +- name: destination.geo.region_name + external: ecs +- name: destination.ip + external: ecs +- name: destination.port + external: ecs +- name: ecs.version + external: ecs +- name: message + external: ecs +- name: event.action + external: ecs +- name: event.category + external: ecs +- name: event.created + external: ecs +- name: event.id + external: ecs +- name: event.ingested + external: ecs +- name: event.kind + external: ecs +- name: event.type + external: ecs +- name: file.mime_type + external: ecs +- name: file.size + external: ecs +- name: network.community_id + external: ecs +- name: network.protocol + external: ecs +- name: host.ip + external: ecs +- name: related.ip + external: ecs +- name: related.user + external: ecs +- name: source.address + external: ecs +- name: source.as.number + external: ecs +- name: source.as.organization.name + external: ecs +- name: geo.continent_name + external: ecs +- name: geo.country_iso_code + external: ecs +- name: geo.country_name + external: ecs +- name: geo.location + external: ecs +- name: geo.city_name + external: ecs +- name: log.level + external: ecs +- name: source.geo.city_name + external: ecs +- name: source.geo.continent_name + external: ecs +- name: source.geo.country_iso_code + external: ecs +- name: source.geo.country_name + external: ecs +- name: source.geo.location + external: ecs +- name: source.geo.name + external: ecs +- name: source.geo.region_iso_code + external: ecs +- name: source.geo.region_name + external: ecs +- name: source.ip + external: ecs +- name: source.port + external: ecs +- name: user.full_name + external: ecs +- name: user.domain + external: ecs +- name: user.name + external: ecs +- name: user.id + external: ecs +- name: user.name + external: ecs +- name: tags + external: ecs +- name: url.original + external: ecs +- name: http.request.bytes + external: ecs +- name: http.request.method + external: ecs +- name: http.response.bytes + external: ecs +- name: http.response.status_code + external: ecs +- name: http.version + external: ecs +- name: tls.version + external: ecs +- name: tls.version_protocol + external: ecs +- name: user_agent.original + external: ecs +- name: user_agent.device.name + external: ecs +- name: user_agent.name + external: ecs +- name: user_agent.os.full + external: ecs +- name: user_agent.os.name + external: ecs +- name: user_agent.os.version + external: ecs +- name: user_agent.version + external: ecs diff --git a/packages/azure_frontdoor/data_stream/access/fields/fields.yml b/packages/azure_frontdoor/data_stream/access/fields/fields.yml new file mode 100644 index 00000000000..60a2155dbbe --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/fields/fields.yml @@ -0,0 +1,48 @@ +- name: azure.frontdoor + type: group + fields: + - name: resource_id + type: keyword + description: Azure Resource ID. + - name: category + type: keyword + description: Azure frontdoor category name. + - name: operation_name + type: keyword + description: Azure operation name. + - name: tracking_reference + type: keyword + description: The unique reference string that identifies a request served by AFD, also sent as X-Azure-Ref header to the client. Required for searching details in the access logs for a specific request. + - name: access + type: group + fields: + - name: time_to_first_byte + type: keyword + description: The length of time in milliseconds from AFD receives the request to the time the first byte gets sent to client, as measured on Azure Front Door. This property doesn't measure the client data. + - name: time_taken + type: keyword + description: The length of time from the time AFD edge server receives a client's request to the time that AFD sends the last byte of response to client, in milliseconds. This field doesn't take into account network latency and TCP buffering. + - name: time + type: keyword + description: The date and time when the AFD edge delivered requested contents to client (in UTC). + - name: rules_engine_match_names + type: keyword + description: The names of the rules that were processed. + - name: routing_rule_name + type: keyword + description: The name of the route that the request matched. + - name: pop + type: keyword + description: The edge pop, which responded to the user request. + - name: is_received_from_client + type: boolean + description: Boolean value. + - name: backend_hostname + type: keyword + description: The host name in the request from client. If you enable custom domains and have wildcard domain (*.contoso.com), hostname is a.contoso.com. if you use Azure Front Door domain (contoso.azurefd.net), hostname is contoso.azurefd.net. + - name: error_info + type: keyword + description: This field provides detailed info of the error token for each response. + - name: cache_status + type: keyword + description: Provides the status code of how the request gets handled by the CDN service when it comes to caching. diff --git a/packages/azure_frontdoor/data_stream/access/manifest.yml b/packages/azure_frontdoor/data_stream/access/manifest.yml new file mode 100644 index 00000000000..e08d08915a6 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/manifest.yml @@ -0,0 +1,32 @@ +title: "FrontDoor Access" +type: logs +streams: + - input: "azure-eventhub" + template_path: "azure-eventhub.yml.hbs" + title: "Azure Frontdoor Access logs" + description: "Collect Azure frontdoor access logs using azure-eventhub input" + vars: + - name: tags + type: text + title: Tags + multi: true + required: true + show_user: false + default: + - azure-frontdoor-access + - forwarded + - name: preserve_original_event + required: true + show_user: true + title: Preserve original event + description: Preserves a raw copy of the original event, added to the field `event.original` + type: bool + multi: false + default: false + - name: processors + type: yaml + title: Processors + multi: false + required: false + show_user: false + description: "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details. " diff --git a/packages/azure_frontdoor/data_stream/access/sample_event.json b/packages/azure_frontdoor/data_stream/access/sample_event.json new file mode 100644 index 00000000000..ed4a330c384 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/access/sample_event.json @@ -0,0 +1,116 @@ +{ + "@timestamp": "2021-12-15T03:36:54.005Z", + "agent": { + "ephemeral_id": "4c506c0d-6542-4a1d-a552-405ffaf54291", + "id": "d7426e8a-1535-4d9a-8f1e-1d5eab23567b", + "name": "docker-fleet-agent", + "type": "filebeat", + "version": "8.6.0" + }, + "azure": { + "frontdoor": { + "access": { + "backend_hostname": "samplev6erp.azurewebsites.net:443", + "cache_status": "CONFIG_NOCACHE", + "error_info": "NoError", + "is_received_from_client": true, + "pop": "SGE", + "routing_rule_name": "erp", + "rules_engine_match_names": [], + "time_taken": "3.603", + "time_to_first_byte": "3.603" + }, + "category": "FrontdoorAccessLog", + "operation_name": "Microsoft.Network/FrontDoor/AccessLog/Write", + "resource_id": "/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD", + "tracking_reference": "00mK5YQAAAADK3xUiPx4/T51HuDizj0XAU0dFRURHRTA5MjAAZGIyMTEzMjYtZmUyZi00MGFmLTkwODMtNzBlMmEyZmFkZmY3" + } + }, + "client": { + "address": "2400:ac40:60b:7aeb:418d:7c32:ac90:e100", + "ip": "2400:ac40:60b:7aeb:418d:7c32:ac90:e100", + "port": 65238 + }, + "cloud": { + "provider": "azure" + }, + "data_stream": { + "dataset": "azure_frontdoor.access", + "namespace": "ep", + "type": "logs" + }, + "ecs": { + "version": "8.5.0" + }, + "elastic_agent": { + "id": "d7426e8a-1535-4d9a-8f1e-1d5eab23567b", + "snapshot": false, + "version": "8.6.0" + }, + "event": { + "agent_id_status": "verified", + "category": [ + "network" + ], + "dataset": "azure_frontdoor.access", + "ingested": "2023-02-02T10:12:54Z", + "type": [ + "connection" + ] + }, + "http": { + "request": { + "bytes": 3081, + "method": "POST" + }, + "response": { + "bytes": 3191, + "status_code": 200 + }, + "version": "2.0.0.0" + }, + "input": { + "type": "filestream" + }, + "log": { + "file": { + "path": "/tmp/service_logs/fdaccess.log" + }, + "offset": 0 + }, + "network": { + "protocol": "HTTPS" + }, + "source": { + "as": { + "number": 237, + "organization": { + "name": "Merit Network Inc." + } + } + }, + "tags": [ + "azure-frontdoor-access", + "forwarded" + ], + "tls": { + "version": "1.2", + "version_protocol": "TLS" + }, + "url": { + "original": "https://erp.testcloud.com:443/Dashboard/getTopStockList" + }, + "user_agent": { + "device": { + "name": "Other" + }, + "name": "Chrome", + "original": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36", + "os": { + "full": "Windows 10", + "name": "Windows", + "version": "10" + }, + "version": "96.0.4664.93" + } +} \ No newline at end of file diff --git a/packages/azure_frontdoor/data_stream/waf/_dev/test/pipeline/test-common-config.yml b/packages/azure_frontdoor/data_stream/waf/_dev/test/pipeline/test-common-config.yml new file mode 100644 index 00000000000..e11f3ae9932 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/_dev/test/pipeline/test-common-config.yml @@ -0,0 +1,6 @@ +dynamic_fields: + event.ingested: ".*" +fields: + tags: + - preserve_original_event + - azure-frontdoor-access diff --git a/packages/azure_frontdoor/data_stream/waf/_dev/test/pipeline/test-fdwaf.log b/packages/azure_frontdoor/data_stream/waf/_dev/test/pipeline/test-fdwaf.log new file mode 100644 index 00000000000..2a8d72d97f6 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/_dev/test/pipeline/test-fdwaf.log @@ -0,0 +1,3 @@ +{"category":"FrontdoorWebApplicationFirewallLog","operationName":"Microsoft.Network/FrontDoor/WebApplicationFirewallLog/Write","properties":{"action":"Log","clientIP":"216.160.83.56","clientPort":"56094","details":{"matches":[]},"host":"connect.testcloud.com","policy":"waf2","policyMode":"detection","requestUri":"https://connect.testcloud.com:443/connect_v2/module001/serviceAttendance/checkvalidUser1","ruleName":"AllowMyanmar","socketIP":"216.160.83.56","trackingReference":"09tTJYQAAAAAV8VyBP8m1Qo+8A3qdd2DuU0lOMzBFREdFMDIxOABkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc="},"resourceId":"/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD","time":"2021-12-27T15:00:06.6330668Z"} +{"category":"FrontdoorWebApplicationFirewallLog","operationName":"Microsoft.Network/FrontDoor/WebApplicationFirewallLog/Write","properties":{"action":"Block","clientIP":"81.2.69.142","clientPort":"59781","details":{"data":"Matched Data: {\"selectPeriod\":\"0000\",\"fromDate\":\"20210701\",\"toDate\":\"20211231\",\"checkDate\":\"20211226\",\"ccSyskey\":\" found within CookieValue:w_db_ibp: {\"selectPeriod\":\"0000\",\"fromDate\":\"20210701\",\"toDate\":\"20211231\",\"checkDate\":\"20211226\",\"ccSyskey\":\"","matches":[{"matchVariableName":"CookieValue:w_db_ibp","matchVariableValue":"{\"selectPeriod\":\"0000\",\"fromDate\":\"20210701\",\"toDate\":\"20211231\",\"checkDate\":\"20211226\",\"ccSyskey\":\""},{"matchVariableName":"CookieValue:w_solist_ibp","matchVariableValue":"{\"refNo\":\"\",\"secRefNo\":\"\",\"crossRefNo\":\"\",\"custCodeOpt\":\"c\",\"custCode\":\"\",\"custNameOpt\":\"c\",\"custNam"},{"matchVariableName":"CookieValue:w_pilist_ibp","matchVariableValue":"{\"refNo\":\"\",\"secRefNo\":\"\",\"crossRef\":\"\",\"status\":\"0\",\"venCodeOpt\":\"c\",\"venCode\":\"\",\"venNameOpt\":\"c\","},{"matchVariableName":"CookieValue:w_ah_ibp","matchVariableValue":"{\"selectedAccCat\":0,\"showTrial\":false,\"showAmt\":false,\"isCc\":false,\"isDept\":false,\"ccSyskey\":\"-1\",\"d"},{"matchVariableName":"CookieValue:w_silist_ibp","matchVariableValue":"{\"refNo\":\"\",\"secRefNo\":\"\",\"crossRefNo\":\"\",\"custCodeOpt\":\"c\",\"custCode\":\"\",\"custNameOpt\":\"c\",\"custNam"}],"msg":"Detects classic SQL injection probings 1/3"},"host":"erp.testcloud.com","policy":"waf2","policyMode":"detection","requestUri":"https://erp.testcloud.com:443/accountcategory/getAccountCategory","ruleName":"DefaultRuleSet-1.0-SQLI-942330","socketIP":"81.2.69.142","trackingReference":"0vePJYQAAAAB9WgG3hg2gTY6gNVGplMGWS1VMMzBFREdFMTAxNgBkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc="},"resourceId":"/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD","time":"2021-12-27T16:03:09.8128356Z"} +{''"records"'': [{"time":"2021-02-02T07:15:37.3640748Z","resourceId":"/SUBSCRIPTIONS/saDFEEQW-JESSIE","category":"FrontdoorAccessLog"}]} \ No newline at end of file diff --git a/packages/azure_frontdoor/data_stream/waf/_dev/test/pipeline/test-fdwaf.log-expected.json b/packages/azure_frontdoor/data_stream/waf/_dev/test/pipeline/test-fdwaf.log-expected.json new file mode 100644 index 00000000000..c73cb83db27 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/_dev/test/pipeline/test-fdwaf.log-expected.json @@ -0,0 +1,133 @@ +{ + "expected": [ + { + "@timestamp": "2021-12-27T15:00:06.633Z", + "azure": { + "frontdoor": { + "category": "FrontdoorWebApplicationFirewallLog", + "operation_name": "Microsoft.Network/FrontDoor/WebApplicationFirewallLog/Write", + "resource_id": "/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD", + "tracking_reference": "09tTJYQAAAAAV8VyBP8m1Qo+8A3qdd2DuU0lOMzBFREdFMDIxOABkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc=", + "waf": { + "details": {}, + "policy": "waf2", + "policy_mode": "detection" + } + } + }, + "client": { + "address": "216.160.83.56", + "ip": "216.160.83.56", + "port": 56094 + }, + "cloud": { + "provider": "azure" + }, + "ecs": { + "version": "8.6.0" + }, + "event": { + "action": "Log", + "category": [ + "network" + ], + "type": [ + "connection" + ] + }, + "rule": { + "name": "AllowMyanmar" + }, + "source": { + "as": { + "number": 209 + }, + "geo": { + "city_name": "Milton", + "continent_name": "North America", + "country_iso_code": "US", + "country_name": "United States", + "location": { + "lat": 47.2513, + "lon": -122.3149 + }, + "region_iso_code": "US-WA", + "region_name": "Washington" + } + }, + "tags": [ + "preserve_original_event", + "azure-frontdoor-access" + ], + "url": { + "domain": "connect.testcloud.com", + "original": "https://connect.testcloud.com:443/connect_v2/module001/serviceAttendance/checkvalidUser1" + } + }, + { + "@timestamp": "2021-12-27T16:03:09.812Z", + "azure": { + "frontdoor": { + "category": "FrontdoorWebApplicationFirewallLog", + "operation_name": "Microsoft.Network/FrontDoor/WebApplicationFirewallLog/Write", + "resource_id": "/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD", + "tracking_reference": "0vePJYQAAAAB9WgG3hg2gTY6gNVGplMGWS1VMMzBFREdFMTAxNgBkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc=", + "waf": { + "details": { + "data": "Matched Data: {\"selectPeriod\":\"0000\",\"fromDate\":\"20210701\",\"toDate\":\"20211231\",\"checkDate\":\"20211226\",\"ccSyskey\":\" found within CookieValue:w_db_ibp: {\"selectPeriod\":\"0000\",\"fromDate\":\"20210701\",\"toDate\":\"20211231\",\"checkDate\":\"20211226\",\"ccSyskey\":\"", + "msg": "Detects classic SQL injection probings 1/3" + }, + "policy": "waf2", + "policy_mode": "detection" + } + } + }, + "client": { + "address": "81.2.69.142", + "ip": "81.2.69.142", + "port": 59781 + }, + "cloud": { + "provider": "azure" + }, + "ecs": { + "version": "8.6.0" + }, + "event": { + "action": "Block", + "category": [ + "network" + ], + "type": [ + "connection" + ] + }, + "rule": { + "name": "DefaultRuleSet-1.0-SQLI-942330" + }, + "source": { + "geo": { + "city_name": "London", + "continent_name": "Europe", + "country_iso_code": "GB", + "country_name": "United Kingdom", + "location": { + "lat": 51.5142, + "lon": -0.0931 + }, + "region_iso_code": "GB-ENG", + "region_name": "England" + } + }, + "tags": [ + "preserve_original_event", + "azure-frontdoor-access" + ], + "url": { + "domain": "erp.testcloud.com", + "original": "https://erp.testcloud.com:443/accountcategory/getAccountCategory" + } + }, + null + ] +} \ No newline at end of file diff --git a/packages/azure_frontdoor/data_stream/waf/agent/stream/azure-eventhub.yml.hbs b/packages/azure_frontdoor/data_stream/waf/agent/stream/azure-eventhub.yml.hbs new file mode 100644 index 00000000000..18701a049f6 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/agent/stream/azure-eventhub.yml.hbs @@ -0,0 +1,33 @@ +{{#if connection_string}} +connection_string: {{connection_string}} +{{/if}} +{{#if eventhub}} +eventhub: {{eventhub}} +storage_account_container: filebeat-activitylogs-{{eventhub}} +{{/if}} +{{#if consumer_group}} +consumer_group: {{consumer_group}} +{{/if}} +{{#if storage_account}} +storage_account: {{storage_account}} +{{/if}} +{{#if storage_account_key}} +storage_account_key: {{storage_account_key}} +{{/if}} +{{#if resource_manager_endpoint}} +resource_manager_endpoint: {{resource_manager_endpoint}} +{{/if}} +tags: +{{#if preserve_original_event}} + - preserve_original_event +{{/if}} +{{#each tags as |tag|}} + - {{tag}} +{{/each}} +{{#contains "forwarded" tags}} +publisher_pipeline.disable_host: true +{{/contains}} +{{#if processors}} +processors: +{{processors}} +{{/if}} diff --git a/packages/azure_frontdoor/data_stream/waf/elasticsearch/ingest_pipeline/default.yml b/packages/azure_frontdoor/data_stream/waf/elasticsearch/ingest_pipeline/default.yml new file mode 100644 index 00000000000..827f908bfd8 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/elasticsearch/ingest_pipeline/default.yml @@ -0,0 +1,125 @@ +--- +description: Pipeline for processing azure frontdoor waf logs +processors: + - set: + field: ecs.version + value: "8.6.0" + - set: + field: event.category + value: [network] + - set: + field: event.type + value: [connection] + - rename: + field: message + target_field: event.original + ignore_missing: true + - set: + field: cloud.provider + value: azure + - drop: + description: Drop if inavlid json + if: 'ctx.event?.original != null && ctx.event.original.contains("records")' + - json: + field: event.original + target_field: azure.frontdoor.waf + - rename: + field: azure.frontdoor.waf.resourceId + target_field: azure.frontdoor.resource_id + ignore_missing: true + - rename: + field: azure.frontdoor.waf.operationName + target_field: azure.frontdoor.operation_name + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.trackingReference + target_field: azure.frontdoor.tracking_reference + ignore_missing: true + - rename: + field: azure.frontdoor.waf.category + target_field: azure.frontdoor.category + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.clientIP + target_field: client.ip + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.clientPort + target_field: client.port + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.action + target_field: event.action + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.socketIP + target_field: client.address + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.ruleName + target_field: rule.name + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.details + target_field: azure.frontdoor.waf.details + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.host + target_field: url.domain + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.policy + target_field: azure.frontdoor.waf.policy + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.policyMode + target_field: azure.frontdoor.waf.policy_mode + ignore_missing: true + - rename: + field: azure.frontdoor.waf.properties.requestUri + target_field: url.original + ignore_missing: true + - convert: + field: client.port + type: long + ignore_missing: true + + - date: + field: azure.frontdoor.waf.time + target_field: "@timestamp" + formats: + - ISO8601 + + - remove: + field: + - azure.frontdoor.waf.time + - azure.frontdoor.waf.properties + - azure.frontdoor.waf.details.matches + - event.original + ignore_missing: true + + - geoip: + field: client.ip + target_field: source.geo + ignore_missing: true + - geoip: + database_file: GeoLite2-ASN.mmdb + field: client.ip + target_field: source.as + properties: + - asn + - organization_name + ignore_missing: true + - rename: + field: source.as.asn + target_field: source.as.number + ignore_missing: true + - rename: + field: source.as.organization_name + target_field: source.as.organization.name + ignore_missing: true + +on_failure: + - set: + field: error.message + value: "{{ _ingest.on_failure_message }}" diff --git a/packages/azure_frontdoor/data_stream/waf/fields/agent.yml b/packages/azure_frontdoor/data_stream/waf/fields/agent.yml new file mode 100644 index 00000000000..bca66ea4ae0 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/fields/agent.yml @@ -0,0 +1,62 @@ +- name: cloud.account.id + external: ecs +- name: cloud.availability_zone + external: ecs +- name: cloud.instance.id + external: ecs +- name: cloud.instance.name + external: ecs +- name: cloud.machine.type + external: ecs +- name: cloud.provider + external: ecs +- name: cloud.region + external: ecs +- name: cloud.project.id + external: ecs +- name: cloud.image.id + type: keyword + description: Image ID for the cloud instance. +- name: container.id + external: ecs +- name: container.image.name + external: ecs +- name: container.labels + external: ecs +- name: container.name + external: ecs +- name: host.architecture + external: ecs +- name: host.domain + external: ecs +- name: host.hostname + external: ecs +- name: host.id + external: ecs +- name: host.ip + external: ecs +- name: host.mac + external: ecs +- name: host.name + external: ecs +- name: host.os.family + external: ecs +- name: host.os.kernel + external: ecs +- name: host.os.name + external: ecs +- name: host.os.platform + external: ecs +- name: host.os.version + external: ecs +- name: host.type + external: ecs +- name: host.containerized + type: boolean + description: If the host is a container. +- name: host.os.build + type: keyword + description: OS build information. +- name: host.os.codename + type: keyword + description: OS codename, if any. diff --git a/packages/azure_frontdoor/data_stream/waf/fields/base-fields.yml b/packages/azure_frontdoor/data_stream/waf/fields/base-fields.yml new file mode 100644 index 00000000000..f245714ba9e --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/fields/base-fields.yml @@ -0,0 +1,21 @@ +- name: data_stream.type + type: constant_keyword + description: Data stream type. +- name: data_stream.dataset + type: constant_keyword + description: Data stream dataset. +- name: data_stream.namespace + type: constant_keyword + description: Data stream namespace. +- name: '@timestamp' + type: date + description: Event timestamp. +- name: input.type + type: keyword + description: Input type. +- name: log.offset + type: long + description: Log offset. +- name: log.file.path + type: keyword + description: Log file path. diff --git a/packages/azure_frontdoor/data_stream/waf/fields/ecs.yml b/packages/azure_frontdoor/data_stream/waf/fields/ecs.yml new file mode 100644 index 00000000000..f5dacaaec80 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/fields/ecs.yml @@ -0,0 +1,120 @@ +- name: client.ip + external: ecs +- name: client.address + external: ecs +- name: client.port + external: ecs +- name: destination.address + external: ecs +- name: destination.as.number + external: ecs +- name: destination.as.organization.name + external: ecs +- name: destination.geo.city_name + external: ecs +- name: destination.geo.continent_name + external: ecs +- name: destination.geo.country_iso_code + external: ecs +- name: destination.geo.country_name + external: ecs +- name: destination.geo.location + external: ecs +- name: destination.geo.name + external: ecs +- name: destination.geo.region_iso_code + external: ecs +- name: destination.geo.region_name + external: ecs +- name: destination.ip + external: ecs +- name: destination.port + external: ecs +- name: ecs.version + external: ecs +- name: message + external: ecs +- name: event.action + external: ecs +- name: event.category + external: ecs +- name: event.created + external: ecs +- name: event.id + external: ecs +- name: event.ingested + external: ecs +- name: event.kind + external: ecs +- name: event.type + external: ecs +- name: file.mime_type + external: ecs +- name: file.size + external: ecs +- name: network.community_id + external: ecs +- name: network.protocol + external: ecs +- name: host.ip + external: ecs +- name: related.ip + external: ecs +- name: related.user + external: ecs +- name: source.address + external: ecs +- name: source.as.number + external: ecs +- name: source.as.organization.name + external: ecs +- name: geo.continent_name + external: ecs +- name: geo.country_iso_code + external: ecs +- name: geo.country_name + external: ecs +- name: geo.location + external: ecs +- name: geo.city_name + external: ecs +- name: log.level + external: ecs +- name: source.geo.city_name + external: ecs +- name: source.geo.continent_name + external: ecs +- name: source.geo.country_iso_code + external: ecs +- name: source.geo.country_name + external: ecs +- name: source.geo.location + external: ecs +- name: source.geo.name + external: ecs +- name: source.geo.region_iso_code + external: ecs +- name: source.geo.region_name + external: ecs +- name: source.ip + external: ecs +- name: source.port + external: ecs +- name: user.full_name + external: ecs +- name: user.domain + external: ecs +- name: user.name + external: ecs +- name: user.id + external: ecs +- name: user.name + external: ecs +- name: tags + external: ecs +- name: url.original + external: ecs +- name: url.domain + external: ecs +- name: rule.name + external: ecs diff --git a/packages/azure_frontdoor/data_stream/waf/fields/fields.yml b/packages/azure_frontdoor/data_stream/waf/fields/fields.yml new file mode 100644 index 00000000000..f6cefe4fbaf --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/fields/fields.yml @@ -0,0 +1,36 @@ +- name: azure.frontdoor + type: group + fields: + - name: resource_id + type: keyword + description: Azure Resource ID. + - name: category + type: keyword + description: Azure frontdoor category name. + - name: operation_name + type: keyword + description: Azure operation name. + - name: tracking_reference + type: keyword + description: The unique reference string that identifies a request served by AFD, also sent as X-Azure-Ref header to the client. Required for searching details in the access logs for a specific request. + - name: waf + type: group + fields: + - name: time + type: keyword + description: The date and time when the AFD edge delivered requested contents to client (in UTC). + - name: policy + type: keyword + description: WAF policy name. + - name: policy_mode + type: keyword + description: WAF policy mode. + - name: details + type: group + fields: + - name: data + type: keyword + description: Detail data. + - name: msg + type: keyword + description: Detail msg. diff --git a/packages/azure_frontdoor/data_stream/waf/manifest.yml b/packages/azure_frontdoor/data_stream/waf/manifest.yml new file mode 100644 index 00000000000..ac12feec83a --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/manifest.yml @@ -0,0 +1,32 @@ +title: "FrontDoor WAF" +type: logs +streams: + - input: "azure-eventhub" + template_path: "azure-eventhub.yml.hbs" + title: "Azure Frontdoor WAF logs" + description: "Collect Azure frontdoor waf logs using azure-eventhub input" + vars: + - name: tags + type: text + title: Tags + multi: true + required: true + show_user: false + default: + - azure-frontdoor-waf + - forwarded + - name: preserve_original_event + required: true + show_user: true + title: Preserve original event + description: Preserves a raw copy of the original event, added to the field `event.original` + type: bool + multi: false + default: false + - name: processors + type: yaml + title: Processors + multi: false + required: false + show_user: false + description: "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details. " diff --git a/packages/azure_frontdoor/data_stream/waf/sample_event.json b/packages/azure_frontdoor/data_stream/waf/sample_event.json new file mode 100644 index 00000000000..7ae94c5b224 --- /dev/null +++ b/packages/azure_frontdoor/data_stream/waf/sample_event.json @@ -0,0 +1,80 @@ +{ + "@timestamp": "2021-12-27T15:00:06.633Z", + "agent": { + "ephemeral_id": "0d8103f6-3567-4591-9d9e-027a17ad7d11", + "id": "96bfc189-b7b0-43a7-8d45-a95fdac6425b", + "name": "docker-fleet-agent", + "type": "filebeat", + "version": "8.5.0" + }, + "azure": { + "frontdoor": { + "category": "FrontdoorWebApplicationFirewallLog", + "operation_name": "Microsoft.Network/FrontDoor/WebApplicationFirewallLog/Write", + "resource_id": "/SUBSCRIPTIONS/49D1B571-1CBE-402D-B523-AFEE3C19B64E/RESOURCEGROUPS/WAF-RG/PROVIDERS/MICROSOFT.NETWORK/FRONTDOORS/TESTCLOUD", + "tracking_reference": "09tTJYQAAAAAV8VyBP8m1Qo+8A3qdd2DuU0lOMzBFREdFMDIxOABkYjIxMTMyNi1mZTJmLTQwYWYtOTA4My03MGUyYTJmYWRmZjc=", + "waf": { + "details": {}, + "policy": "waf2", + "policy_mode": "detection" + } + } + }, + "client": { + "address": "8.38.147.74", + "ip": "8.38.147.74", + "port": 56094 + }, + "cloud": { + "provider": "azure" + }, + "data_stream": { + "dataset": "azure_frontdoor.waf", + "namespace": "ep", + "type": "logs" + }, + "ecs": { + "version": "8.5.0" + }, + "elastic_agent": { + "id": "96bfc189-b7b0-43a7-8d45-a95fdac6425b", + "snapshot": true, + "version": "8.5.0" + }, + "event": { + "action": "Log", + "agent_id_status": "verified", + "category": [ + "network" + ], + "dataset": "azure_frontdoor.waf", + "ingested": "2022-12-07T03:58:03Z", + "timezone": "+00:00", + "type": [ + "connection" + ] + }, + "host": { + "name": "docker-fleet-agent" + }, + "input": { + "type": "log" + }, + "log": { + "file": { + "path": "/tmp/service_logs/fdwaf.log" + }, + "offset": 0 + }, + "rule": { + "name": "AllowMyanmar" + }, + "tags": [ + "azure-frontdoor-waf", + "forwarded" + ], + "url": { + "domain": "connect.testcloud.com", + "original": "https://connect.testcloud.com:443/connect_v2/module001/serviceAttendance/checkvalidUser1" + } +} \ No newline at end of file diff --git a/packages/azure_frontdoor/docs/README.md b/packages/azure_frontdoor/docs/README.md new file mode 100644 index 00000000000..3e1c84cc016 --- /dev/null +++ b/packages/azure_frontdoor/docs/README.md @@ -0,0 +1,307 @@ +# Azure Frontdoor Logs Integration + +The azure frontdoor logs integration retrieves different types of log data from AFD. +Azure Front Door provides different logging to help you track, monitor, and debug your Front Door. + +- Access logs have detailed information about every request that AFD receives and help you analyze and monitor access patterns, and debug issues. +- Activity logs provide visibility into the operations done on Azure resources. +- Health Probe logs provides the logs for every failed probe to your origin. +- Web Application Firewall (WAF) logs provide detailed information of requests that gets logged through either detection or prevention mode of an Azure Front Door endpoint. A custom domain that gets configured with WAF can also be viewed through these logs. + +## Data streams + +This integration collects two types of data streams: + +- access log +- waf logs + +## Requirements + +### Credentials + +`eventhub` : +_string_ +Is the fully managed, real-time data ingestion service. + +`consumer_group` : +_string_ +The publish/subscribe mechanism of Event Hubs is enabled through consumer groups. A consumer group is a view (state, position, or offset) of an entire event hub. Consumer groups enable multiple consuming applications to each have a separate view of the event stream, and to read the stream independently at their own pace and with their own offsets. +Default value: `$Default` + +`connection_string` : +_string_ +The connection string required to communicate with Event Hubs, steps here https://docs.microsoft.com/en-us/azure/event-hubs/event-hubs-get-connection-string. + +A Blob Storage account is required in order to store/retrieve/update the offset or state of the eventhub messages. This means that after stopping the filebeat azure module it can start back up at the spot that it stopped processing messages. + +`storage_account` : +_string_ +The name of the storage account the state/offsets will be stored and updated. + +`storage_account_key` : +_string_ +The storage account key, this key will be used to authorize access to data in your storage account. + +`resource_manager_endpoint` : +_string_ +Optional, by default we are using the azure public environment, to override, users can provide a specific resource manager endpoint in order to use a different azure environment. +Ex: +https://management.chinacloudapi.cn/ for azure ChinaCloud +https://management.microsoftazure.de/ for azure GermanCloud +https://management.azure.com/ for azure PublicCloud +https://management.usgovcloudapi.net/ for azure USGovernmentCloud +Users can also use this in case of a Hybrid Cloud model, where one may define their own endpoints. + +## Acceess Logs + +**Exported fields** + +| Field | Description | Type | +|---|---|---| +| @timestamp | Event timestamp. | date | +| azure.frontdoor.access.backend_hostname | The host name in the request from client. If you enable custom domains and have wildcard domain (\*.contoso.com), hostname is a.contoso.com. if you use Azure Front Door domain (contoso.azurefd.net), hostname is contoso.azurefd.net. | keyword | +| azure.frontdoor.access.cache_status | Provides the status code of how the request gets handled by the CDN service when it comes to caching. | keyword | +| azure.frontdoor.access.error_info | This field provides detailed info of the error token for each response. | keyword | +| azure.frontdoor.access.is_received_from_client | Boolean value. | boolean | +| azure.frontdoor.access.pop | The edge pop, which responded to the user request. | keyword | +| azure.frontdoor.access.routing_rule_name | The name of the route that the request matched. | keyword | +| azure.frontdoor.access.rules_engine_match_names | The names of the rules that were processed. | keyword | +| azure.frontdoor.access.time | The date and time when the AFD edge delivered requested contents to client (in UTC). | keyword | +| azure.frontdoor.access.time_taken | The length of time from the time AFD edge server receives a client's request to the time that AFD sends the last byte of response to client, in milliseconds. This field doesn't take into account network latency and TCP buffering. | keyword | +| azure.frontdoor.access.time_to_first_byte | The length of time in milliseconds from AFD receives the request to the time the first byte gets sent to client, as measured on Azure Front Door. This property doesn't measure the client data. | keyword | +| azure.frontdoor.category | Azure frontdoor category name. | keyword | +| azure.frontdoor.operation_name | Azure operation name. | keyword | +| azure.frontdoor.resource_id | Azure Resource ID. | keyword | +| azure.frontdoor.tracking_reference | The unique reference string that identifies a request served by AFD, also sent as X-Azure-Ref header to the client. Required for searching details in the access logs for a specific request. | keyword | +| client.address | Some event client addresses are defined ambiguously. The event will sometimes list an IP, a domain or a unix socket. You should always store the raw address in the `.address` field. Then it should be duplicated to `.ip` or `.domain`, depending on which one it is. | keyword | +| client.ip | IP address of the client (IPv4 or IPv6). | ip | +| client.port | Port of the client. | long | +| cloud.account.id | The cloud account or organization id used to identify different entities in a multi-tenant environment. Examples: AWS account id, Google Cloud ORG Id, or other unique identifier. | keyword | +| cloud.availability_zone | Availability zone in which this host, resource, or service is located. | keyword | +| cloud.image.id | Image ID for the cloud instance. | keyword | +| cloud.instance.id | Instance ID of the host machine. | keyword | +| cloud.instance.name | Instance name of the host machine. | keyword | +| cloud.machine.type | Machine type of the host machine. | keyword | +| cloud.project.id | The cloud project identifier. Examples: Google Cloud Project id, Azure Project id. | keyword | +| cloud.provider | Name of the cloud provider. Example values are aws, azure, gcp, or digitalocean. | keyword | +| cloud.region | Region in which this host, resource, or service is located. | keyword | +| container.id | Unique container id. | keyword | +| container.image.name | Name of the image the container was built on. | keyword | +| container.labels | Image labels. | object | +| container.name | Container name. | keyword | +| data_stream.dataset | Data stream dataset. | constant_keyword | +| data_stream.namespace | Data stream namespace. | constant_keyword | +| data_stream.type | Data stream type. | constant_keyword | +| destination.address | Some event destination addresses are defined ambiguously. The event will sometimes list an IP, a domain or a unix socket. You should always store the raw address in the `.address` field. Then it should be duplicated to `.ip` or `.domain`, depending on which one it is. | keyword | +| destination.as.number | Unique number allocated to the autonomous system. The autonomous system number (ASN) uniquely identifies each network on the Internet. | long | +| destination.as.organization.name | Organization name. | keyword | +| destination.as.organization.name.text | Multi-field of `destination.as.organization.name`. | match_only_text | +| destination.geo.city_name | City name. | keyword | +| destination.geo.continent_name | Name of the continent. | keyword | +| destination.geo.country_iso_code | Country ISO code. | keyword | +| destination.geo.country_name | Country name. | keyword | +| destination.geo.location | Longitude and latitude. | geo_point | +| destination.geo.name | User-defined description of a location, at the level of granularity they care about. Could be the name of their data centers, the floor number, if this describes a local physical entity, city names. Not typically used in automated geolocation. | keyword | +| destination.geo.region_iso_code | Region ISO code. | keyword | +| destination.geo.region_name | Region name. | keyword | +| destination.ip | IP address of the destination (IPv4 or IPv6). | ip | +| destination.port | Port of the destination. | long | +| ecs.version | ECS version this event conforms to. `ecs.version` is a required field and must exist in all events. When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events. | keyword | +| event.action | The action captured by the event. This describes the information in the event. It is more specific than `event.category`. Examples are `group-add`, `process-started`, `file-created`. The value is normally defined by the implementer. | keyword | +| event.category | This is one of four ECS Categorization Fields, and indicates the second level in the ECS category hierarchy. `event.category` represents the "big buckets" of ECS categories. For example, filtering on `event.category:process` yields all events relating to process activity. This field is closely related to `event.type`, which is used as a subcategory. This field is an array. This will allow proper categorization of some events that fall in multiple categories. | keyword | +| event.created | event.created contains the date/time when the event was first read by an agent, or by your pipeline. This field is distinct from @timestamp in that @timestamp typically contain the time extracted from the original event. In most situations, these two timestamps will be slightly different. The difference can be used to calculate the delay between your source generating an event, and the time when your agent first processed it. This can be used to monitor your agent's or pipeline's ability to keep up with your event source. In case the two timestamps are identical, @timestamp should be used. | date | +| event.id | Unique ID to describe the event. | keyword | +| event.ingested | Timestamp when an event arrived in the central data store. This is different from `@timestamp`, which is when the event originally occurred. It's also different from `event.created`, which is meant to capture the first time an agent saw the event. In normal conditions, assuming no tampering, the timestamps should chronologically look like this: `@timestamp` \< `event.created` \< `event.ingested`. | date | +| event.kind | This is one of four ECS Categorization Fields, and indicates the highest level in the ECS category hierarchy. `event.kind` gives high-level information about what type of information the event contains, without being specific to the contents of the event. For example, values of this field distinguish alert events from metric events. The value of this field can be used to inform how these kinds of events should be handled. They may warrant different retention, different access control, it may also help understand whether the data coming in at a regular interval or not. | keyword | +| event.type | This is one of four ECS Categorization Fields, and indicates the third level in the ECS category hierarchy. `event.type` represents a categorization "sub-bucket" that, when used along with the `event.category` field values, enables filtering events down to a level appropriate for single visualization. This field is an array. This will allow proper categorization of some events that fall in multiple event types. | keyword | +| file.mime_type | MIME type should identify the format of the file or stream of bytes using https://www.iana.org/assignments/media-types/media-types.xhtml[IANA official types], where possible. When more than one type is applicable, the most specific type should be used. | keyword | +| file.size | File size in bytes. Only relevant when `file.type` is "file". | long | +| geo.city_name | City name. | keyword | +| geo.continent_name | Name of the continent. | keyword | +| geo.country_iso_code | Country ISO code. | keyword | +| geo.country_name | Country name. | keyword | +| geo.location | Longitude and latitude. | geo_point | +| host.architecture | Operating system architecture. | keyword | +| host.containerized | If the host is a container. | boolean | +| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword | +| host.hostname | Hostname of the host. It normally contains what the `hostname` command returns on the host machine. | keyword | +| host.id | Unique host id. As hostname is not always unique, use values that are meaningful in your environment. Example: The current usage of `beat.name`. | keyword | +| host.ip | Host ip addresses. | ip | +| host.mac | Host MAC addresses. The notation format from RFC 7042 is suggested: Each octet (that is, 8-bit byte) is represented by two [uppercase] hexadecimal digits giving the value of the octet as an unsigned integer. Successive octets are separated by a hyphen. | keyword | +| host.name | Name of the host. It can contain what `hostname` returns on Unix systems, the fully qualified domain name, or a name specified by the user. The sender decides which value to use. | keyword | +| host.os.build | OS build information. | keyword | +| host.os.codename | OS codename, if any. | keyword | +| host.os.family | OS family (such as redhat, debian, freebsd, windows). | keyword | +| host.os.kernel | Operating system kernel version as a raw string. | keyword | +| host.os.name | Operating system name, without the version. | keyword | +| host.os.name.text | Multi-field of `host.os.name`. | match_only_text | +| host.os.platform | Operating system platform (such centos, ubuntu, windows). | keyword | +| host.os.version | Operating system version as a raw string. | keyword | +| host.type | Type of host. For Cloud providers this can be the machine type like `t2.medium`. If vm, this could be the container, for example, or other information meaningful in your environment. | keyword | +| http.request.bytes | Total size in bytes of the request (body and headers). | long | +| http.request.method | HTTP request method. The value should retain its casing from the original event. For example, `GET`, `get`, and `GeT` are all considered valid values for this field. | keyword | +| http.response.bytes | Total size in bytes of the response (body and headers). | long | +| http.response.status_code | HTTP response status code. | long | +| http.version | HTTP version. | keyword | +| input.type | Input type. | keyword | +| log.file.path | Log file path. | keyword | +| log.level | Original log level of the log event. If the source of the event provides a log level or textual severity, this is the one that goes in `log.level`. If your source doesn't specify one, you may put your event transport's severity here (e.g. Syslog severity). Some examples are `warn`, `err`, `i`, `informational`. | keyword | +| log.offset | Log offset. | long | +| message | For log events the message field contains the log message, optimized for viewing in a log viewer. For structured logs without an original message field, other fields can be concatenated to form a human-readable summary of the event. If multiple messages exist, they can be combined into one message. | match_only_text | +| network.community_id | A hash of source and destination IPs and ports, as well as the protocol used in a communication. This is a tool-agnostic standard to identify flows. Learn more at https://github.com/corelight/community-id-spec. | keyword | +| network.protocol | In the OSI Model this would be the Application Layer protocol. For example, `http`, `dns`, or `ssh`. The field value must be normalized to lowercase for querying. | keyword | +| related.ip | All of the IPs seen on your event. | ip | +| related.user | All the user names or other user identifiers seen on the event. | keyword | +| source.address | Some event source addresses are defined ambiguously. The event will sometimes list an IP, a domain or a unix socket. You should always store the raw address in the `.address` field. Then it should be duplicated to `.ip` or `.domain`, depending on which one it is. | keyword | +| source.as.number | Unique number allocated to the autonomous system. The autonomous system number (ASN) uniquely identifies each network on the Internet. | long | +| source.as.organization.name | Organization name. | keyword | +| source.as.organization.name.text | Multi-field of `source.as.organization.name`. | match_only_text | +| source.geo.city_name | City name. | keyword | +| source.geo.continent_name | Name of the continent. | keyword | +| source.geo.country_iso_code | Country ISO code. | keyword | +| source.geo.country_name | Country name. | keyword | +| source.geo.location | Longitude and latitude. | geo_point | +| source.geo.name | User-defined description of a location, at the level of granularity they care about. Could be the name of their data centers, the floor number, if this describes a local physical entity, city names. Not typically used in automated geolocation. | keyword | +| source.geo.region_iso_code | Region ISO code. | keyword | +| source.geo.region_name | Region name. | keyword | +| source.ip | IP address of the source (IPv4 or IPv6). | ip | +| source.port | Port of the source. | long | +| tags | List of keywords used to tag each event. | keyword | +| tls.version | Numeric part of the version parsed from the original string. | keyword | +| tls.version_protocol | Normalized lowercase protocol name parsed from original string. | keyword | +| url.original | Unmodified original url as seen in the event source. Note that in network monitoring, the observed URL may be a full URL, whereas in access logs, the URL is often just represented as a path. This field is meant to represent the URL as it was observed, complete or not. | wildcard | +| url.original.text | Multi-field of `url.original`. | match_only_text | +| user.domain | Name of the directory the user is a member of. For example, an LDAP or Active Directory domain name. | keyword | +| user.full_name | User's full name, if available. | keyword | +| user.full_name.text | Multi-field of `user.full_name`. | match_only_text | +| user.id | Unique identifier of the user. | keyword | +| user.name | Short name or login of the user. | keyword | +| user.name.text | Multi-field of `user.name`. | match_only_text | +| user_agent.device.name | Name of the device. | keyword | +| user_agent.name | Name of the user agent. | keyword | +| user_agent.original | Unparsed user_agent string. | keyword | +| user_agent.original.text | Multi-field of `user_agent.original`. | match_only_text | +| user_agent.os.full | Operating system name, including the version or code name. | keyword | +| user_agent.os.full.text | Multi-field of `user_agent.os.full`. | match_only_text | +| user_agent.os.name | Operating system name, without the version. | keyword | +| user_agent.os.name.text | Multi-field of `user_agent.os.name`. | match_only_text | +| user_agent.os.version | Operating system version as a raw string. | keyword | +| user_agent.version | Version of the user agent. | keyword | + + +## WAF Logs + +**Exported fields** + +| Field | Description | Type | +|---|---|---| +| @timestamp | Event timestamp. | date | +| azure.frontdoor.category | Azure frontdoor category name. | keyword | +| azure.frontdoor.operation_name | Azure operation name. | keyword | +| azure.frontdoor.resource_id | Azure Resource ID. | keyword | +| azure.frontdoor.tracking_reference | The unique reference string that identifies a request served by AFD, also sent as X-Azure-Ref header to the client. Required for searching details in the access logs for a specific request. | keyword | +| azure.frontdoor.waf.details.data | Detail data. | keyword | +| azure.frontdoor.waf.details.msg | Detail msg. | keyword | +| azure.frontdoor.waf.policy | WAF policy name. | keyword | +| azure.frontdoor.waf.policy_mode | WAF policy mode. | keyword | +| azure.frontdoor.waf.time | The date and time when the AFD edge delivered requested contents to client (in UTC). | keyword | +| client.address | Some event client addresses are defined ambiguously. The event will sometimes list an IP, a domain or a unix socket. You should always store the raw address in the `.address` field. Then it should be duplicated to `.ip` or `.domain`, depending on which one it is. | keyword | +| client.ip | IP address of the client (IPv4 or IPv6). | ip | +| client.port | Port of the client. | long | +| cloud.account.id | The cloud account or organization id used to identify different entities in a multi-tenant environment. Examples: AWS account id, Google Cloud ORG Id, or other unique identifier. | keyword | +| cloud.availability_zone | Availability zone in which this host, resource, or service is located. | keyword | +| cloud.image.id | Image ID for the cloud instance. | keyword | +| cloud.instance.id | Instance ID of the host machine. | keyword | +| cloud.instance.name | Instance name of the host machine. | keyword | +| cloud.machine.type | Machine type of the host machine. | keyword | +| cloud.project.id | The cloud project identifier. Examples: Google Cloud Project id, Azure Project id. | keyword | +| cloud.provider | Name of the cloud provider. Example values are aws, azure, gcp, or digitalocean. | keyword | +| cloud.region | Region in which this host, resource, or service is located. | keyword | +| container.id | Unique container id. | keyword | +| container.image.name | Name of the image the container was built on. | keyword | +| container.labels | Image labels. | object | +| container.name | Container name. | keyword | +| data_stream.dataset | Data stream dataset. | constant_keyword | +| data_stream.namespace | Data stream namespace. | constant_keyword | +| data_stream.type | Data stream type. | constant_keyword | +| destination.address | Some event destination addresses are defined ambiguously. The event will sometimes list an IP, a domain or a unix socket. You should always store the raw address in the `.address` field. Then it should be duplicated to `.ip` or `.domain`, depending on which one it is. | keyword | +| destination.as.number | Unique number allocated to the autonomous system. The autonomous system number (ASN) uniquely identifies each network on the Internet. | long | +| destination.as.organization.name | Organization name. | keyword | +| destination.as.organization.name.text | Multi-field of `destination.as.organization.name`. | match_only_text | +| destination.geo.city_name | City name. | keyword | +| destination.geo.continent_name | Name of the continent. | keyword | +| destination.geo.country_iso_code | Country ISO code. | keyword | +| destination.geo.country_name | Country name. | keyword | +| destination.geo.location | Longitude and latitude. | geo_point | +| destination.geo.name | User-defined description of a location, at the level of granularity they care about. Could be the name of their data centers, the floor number, if this describes a local physical entity, city names. Not typically used in automated geolocation. | keyword | +| destination.geo.region_iso_code | Region ISO code. | keyword | +| destination.geo.region_name | Region name. | keyword | +| destination.ip | IP address of the destination (IPv4 or IPv6). | ip | +| destination.port | Port of the destination. | long | +| ecs.version | ECS version this event conforms to. `ecs.version` is a required field and must exist in all events. When querying across multiple indices -- which may conform to slightly different ECS versions -- this field lets integrations adjust to the schema version of the events. | keyword | +| event.action | The action captured by the event. This describes the information in the event. It is more specific than `event.category`. Examples are `group-add`, `process-started`, `file-created`. The value is normally defined by the implementer. | keyword | +| event.category | This is one of four ECS Categorization Fields, and indicates the second level in the ECS category hierarchy. `event.category` represents the "big buckets" of ECS categories. For example, filtering on `event.category:process` yields all events relating to process activity. This field is closely related to `event.type`, which is used as a subcategory. This field is an array. This will allow proper categorization of some events that fall in multiple categories. | keyword | +| event.created | event.created contains the date/time when the event was first read by an agent, or by your pipeline. This field is distinct from @timestamp in that @timestamp typically contain the time extracted from the original event. In most situations, these two timestamps will be slightly different. The difference can be used to calculate the delay between your source generating an event, and the time when your agent first processed it. This can be used to monitor your agent's or pipeline's ability to keep up with your event source. In case the two timestamps are identical, @timestamp should be used. | date | +| event.id | Unique ID to describe the event. | keyword | +| event.ingested | Timestamp when an event arrived in the central data store. This is different from `@timestamp`, which is when the event originally occurred. It's also different from `event.created`, which is meant to capture the first time an agent saw the event. In normal conditions, assuming no tampering, the timestamps should chronologically look like this: `@timestamp` \< `event.created` \< `event.ingested`. | date | +| event.kind | This is one of four ECS Categorization Fields, and indicates the highest level in the ECS category hierarchy. `event.kind` gives high-level information about what type of information the event contains, without being specific to the contents of the event. For example, values of this field distinguish alert events from metric events. The value of this field can be used to inform how these kinds of events should be handled. They may warrant different retention, different access control, it may also help understand whether the data coming in at a regular interval or not. | keyword | +| event.type | This is one of four ECS Categorization Fields, and indicates the third level in the ECS category hierarchy. `event.type` represents a categorization "sub-bucket" that, when used along with the `event.category` field values, enables filtering events down to a level appropriate for single visualization. This field is an array. This will allow proper categorization of some events that fall in multiple event types. | keyword | +| file.mime_type | MIME type should identify the format of the file or stream of bytes using https://www.iana.org/assignments/media-types/media-types.xhtml[IANA official types], where possible. When more than one type is applicable, the most specific type should be used. | keyword | +| file.size | File size in bytes. Only relevant when `file.type` is "file". | long | +| geo.city_name | City name. | keyword | +| geo.continent_name | Name of the continent. | keyword | +| geo.country_iso_code | Country ISO code. | keyword | +| geo.country_name | Country name. | keyword | +| geo.location | Longitude and latitude. | geo_point | +| host.architecture | Operating system architecture. | keyword | +| host.containerized | If the host is a container. | boolean | +| host.domain | Name of the domain of which the host is a member. For example, on Windows this could be the host's Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host's LDAP provider. | keyword | +| host.hostname | Hostname of the host. It normally contains what the `hostname` command returns on the host machine. | keyword | +| host.id | Unique host id. As hostname is not always unique, use values that are meaningful in your environment. Example: The current usage of `beat.name`. | keyword | +| host.ip | Host ip addresses. | ip | +| host.mac | Host MAC addresses. The notation format from RFC 7042 is suggested: Each octet (that is, 8-bit byte) is represented by two [uppercase] hexadecimal digits giving the value of the octet as an unsigned integer. Successive octets are separated by a hyphen. | keyword | +| host.name | Name of the host. It can contain what `hostname` returns on Unix systems, the fully qualified domain name, or a name specified by the user. The sender decides which value to use. | keyword | +| host.os.build | OS build information. | keyword | +| host.os.codename | OS codename, if any. | keyword | +| host.os.family | OS family (such as redhat, debian, freebsd, windows). | keyword | +| host.os.kernel | Operating system kernel version as a raw string. | keyword | +| host.os.name | Operating system name, without the version. | keyword | +| host.os.name.text | Multi-field of `host.os.name`. | match_only_text | +| host.os.platform | Operating system platform (such centos, ubuntu, windows). | keyword | +| host.os.version | Operating system version as a raw string. | keyword | +| host.type | Type of host. For Cloud providers this can be the machine type like `t2.medium`. If vm, this could be the container, for example, or other information meaningful in your environment. | keyword | +| input.type | Input type. | keyword | +| log.file.path | Log file path. | keyword | +| log.level | Original log level of the log event. If the source of the event provides a log level or textual severity, this is the one that goes in `log.level`. If your source doesn't specify one, you may put your event transport's severity here (e.g. Syslog severity). Some examples are `warn`, `err`, `i`, `informational`. | keyword | +| log.offset | Log offset. | long | +| message | For log events the message field contains the log message, optimized for viewing in a log viewer. For structured logs without an original message field, other fields can be concatenated to form a human-readable summary of the event. If multiple messages exist, they can be combined into one message. | match_only_text | +| network.community_id | A hash of source and destination IPs and ports, as well as the protocol used in a communication. This is a tool-agnostic standard to identify flows. Learn more at https://github.com/corelight/community-id-spec. | keyword | +| network.protocol | In the OSI Model this would be the Application Layer protocol. For example, `http`, `dns`, or `ssh`. The field value must be normalized to lowercase for querying. | keyword | +| related.ip | All of the IPs seen on your event. | ip | +| related.user | All the user names or other user identifiers seen on the event. | keyword | +| rule.name | The name of the rule or signature generating the event. | keyword | +| source.address | Some event source addresses are defined ambiguously. The event will sometimes list an IP, a domain or a unix socket. You should always store the raw address in the `.address` field. Then it should be duplicated to `.ip` or `.domain`, depending on which one it is. | keyword | +| source.as.number | Unique number allocated to the autonomous system. The autonomous system number (ASN) uniquely identifies each network on the Internet. | long | +| source.as.organization.name | Organization name. | keyword | +| source.as.organization.name.text | Multi-field of `source.as.organization.name`. | match_only_text | +| source.geo.city_name | City name. | keyword | +| source.geo.continent_name | Name of the continent. | keyword | +| source.geo.country_iso_code | Country ISO code. | keyword | +| source.geo.country_name | Country name. | keyword | +| source.geo.location | Longitude and latitude. | geo_point | +| source.geo.name | User-defined description of a location, at the level of granularity they care about. Could be the name of their data centers, the floor number, if this describes a local physical entity, city names. Not typically used in automated geolocation. | keyword | +| source.geo.region_iso_code | Region ISO code. | keyword | +| source.geo.region_name | Region name. | keyword | +| source.ip | IP address of the source (IPv4 or IPv6). | ip | +| source.port | Port of the source. | long | +| tags | List of keywords used to tag each event. | keyword | +| url.domain | Domain of the url, such as "www.elastic.co". In some cases a URL may refer to an IP and/or port directly, without a domain name. In this case, the IP address would go to the `domain` field. If the URL contains a literal IPv6 address enclosed by `[` and `]` (IETF RFC 2732), the `[` and `]` characters should also be captured in the `domain` field. | keyword | +| url.original | Unmodified original url as seen in the event source. Note that in network monitoring, the observed URL may be a full URL, whereas in access logs, the URL is often just represented as a path. This field is meant to represent the URL as it was observed, complete or not. | wildcard | +| url.original.text | Multi-field of `url.original`. | match_only_text | +| user.domain | Name of the directory the user is a member of. For example, an LDAP or Active Directory domain name. | keyword | +| user.full_name | User's full name, if available. | keyword | +| user.full_name.text | Multi-field of `user.full_name`. | match_only_text | +| user.id | Unique identifier of the user. | keyword | +| user.name | Short name or login of the user. | keyword | +| user.name.text | Multi-field of `user.name`. | match_only_text | + diff --git a/packages/azure_frontdoor/img/azure-frontdoor-overview.png b/packages/azure_frontdoor/img/azure-frontdoor-overview.png new file mode 100644 index 00000000000..23463adb217 Binary files /dev/null and b/packages/azure_frontdoor/img/azure-frontdoor-overview.png differ diff --git a/packages/azure_frontdoor/img/front-door.svg b/packages/azure_frontdoor/img/front-door.svg new file mode 100644 index 00000000000..a1be737e469 --- /dev/null +++ b/packages/azure_frontdoor/img/front-door.svg @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/packages/azure_frontdoor/kibana/dashboard/azure_frontdoor-d05e0860-6ea7-11ec-bf35-712f9048d91f.json b/packages/azure_frontdoor/kibana/dashboard/azure_frontdoor-d05e0860-6ea7-11ec-bf35-712f9048d91f.json new file mode 100644 index 00000000000..364071c49c2 --- /dev/null +++ b/packages/azure_frontdoor/kibana/dashboard/azure_frontdoor-d05e0860-6ea7-11ec-bf35-712f9048d91f.json @@ -0,0 +1,1310 @@ +{ + "id": "azure_frontdoor-d05e0860-6ea7-11ec-bf35-712f9048d91f", + "type": "dashboard", + "namespaces": [ + "default" + ], + "updated_at": "2023-02-02T10:06:59.720Z", + "created_at": "2023-02-02T10:06:59.720Z", + "version": "Wzg0MCwxXQ==", + "attributes": { + "description": "Azure Frontdoor Integration Dashboard", + "hits": 0, + "kibanaSavedObjectMeta": { + "searchSourceJSON": { + "filter": [ + { + "$state": { + "store": "appState" + }, + "meta": { + "alias": null, + "disabled": false, + "indexRefName": "kibanaSavedObjectMeta.searchSourceJSON.filter[0].meta.index", + "key": "data_stream.dataset", + "negate": false, + "params": [ + "azure_frontdoor.access", + "azure_frontdoor.waf" + ], + "type": "phrases" + }, + "query": { + "bool": { + "minimum_should_match": 1, + "should": [ + { + "match_phrase": { + "data_stream.dataset": "azure_frontdoor.access" + } + }, + { + "match_phrase": { + "data_stream.dataset": "azure_frontdoor.waf" + } + } + ] + } + } + } + ], + "query": { + "language": "kuery", + "query": "" + } + } + }, + "optionsJSON": { + "hidePanelTitles": false, + "syncColors": false, + "useMargins": true + }, + "panelsJSON": [ + { + "version": "8.6.0", + "type": "lens", + "gridData": { + "h": 13, + "i": "f8012579-e741-44fc-9470-5348fa7a6821", + "w": 24, + "x": 0, + "y": 0 + }, + "panelIndex": "f8012579-e741-44fc-9470-5348fa7a6821", + "embeddableConfig": { + "enhancements": {}, + "attributes": { + "description": "", + "state": { + "datasourceStates": { + "formBased": { + "layers": { + "266caf24-daea-453b-a081-b81a3a1a5d34": { + "columnOrder": [ + "db61d40a-769c-47ad-b7ae-6384624df2ea", + "a6dfa33a-652d-4d16-b4ea-709a9bf51a2b", + "ee54a93c-ed19-4e1b-84ff-52144faec318" + ], + "columns": { + "a6dfa33a-652d-4d16-b4ea-709a9bf51a2b": { + "dataType": "date", + "isBucketed": true, + "label": "@timestamp", + "operationType": "date_histogram", + "params": { + "interval": "auto", + "includeEmptyRows": true + }, + "scale": "interval", + "sourceField": "@timestamp" + }, + "db61d40a-769c-47ad-b7ae-6384624df2ea": { + "dataType": "string", + "isBucketed": true, + "label": "Top values of data_stream.dataset", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "ee54a93c-ed19-4e1b-84ff-52144faec318", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": true, + "size": 5, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "data_stream.dataset" + }, + "ee54a93c-ed19-4e1b-84ff-52144faec318": { + "dataType": "number", + "isBucketed": false, + "label": "Count of records", + "operationType": "count", + "scale": "ratio", + "sourceField": "___records___" + } + }, + "incompleteColumns": {} + } + } + } + }, + "filters": [], + "query": { + "language": "kuery", + "query": "" + }, + "visualization": { + "axisTitlesVisibilitySettings": { + "x": true, + "yLeft": true, + "yRight": true + }, + "fittingFunction": "None", + "gridlinesVisibilitySettings": { + "x": true, + "yLeft": true, + "yRight": true + }, + "labelsOrientation": { + "x": 0, + "yLeft": 0, + "yRight": 0 + }, + "layers": [ + { + "accessors": [ + "ee54a93c-ed19-4e1b-84ff-52144faec318" + ], + "layerId": "266caf24-daea-453b-a081-b81a3a1a5d34", + "layerType": "data", + "position": "top", + "seriesType": "bar_stacked", + "showGridlines": false, + "splitAccessor": "db61d40a-769c-47ad-b7ae-6384624df2ea", + "xAccessor": "a6dfa33a-652d-4d16-b4ea-709a9bf51a2b" + } + ], + "legend": { + "isVisible": true, + "position": "right", + "legendSize": "auto" + }, + "preferredSeriesType": "bar_stacked", + "tickLabelsVisibilitySettings": { + "x": true, + "yLeft": true, + "yRight": true + }, + "valueLabels": "hide", + "yLeftExtent": { + "mode": "full" + }, + "yRightExtent": { + "mode": "full" + } + } + }, + "title": "Logs Over Time [Azure Frontdoor]", + "visualizationType": "lnsXY", + "references": [ + { + "id": "logs-*", + "name": "indexpattern-datasource-current-indexpattern", + "type": "index-pattern" + }, + { + "id": "logs-*", + "name": "indexpattern-datasource-layer-266caf24-daea-453b-a081-b81a3a1a5d34", + "type": "index-pattern" + } + ] + } + } + }, + { + "version": "8.6.0", + "type": "lens", + "gridData": { + "h": 13, + "i": "a318c8ca-32a6-4115-81c2-7448d02f30c1", + "w": 24, + "x": 24, + "y": 0 + }, + "panelIndex": "a318c8ca-32a6-4115-81c2-7448d02f30c1", + "embeddableConfig": { + "enhancements": {}, + "attributes": { + "description": "", + "state": { + "datasourceStates": { + "formBased": { + "layers": { + "0ee62278-341b-4d9d-8f65-44eef424786b": { + "columnOrder": [ + "823d0215-ee4e-4572-8a2a-e39893ece10d", + "74ecbafb-fb61-4678-820e-e0cd221307f4", + "f14be824-7dc6-4399-8491-5777389b1f1c" + ], + "columns": { + "74ecbafb-fb61-4678-820e-e0cd221307f4": { + "dataType": "date", + "isBucketed": true, + "label": "@timestamp", + "operationType": "date_histogram", + "params": { + "interval": "auto", + "includeEmptyRows": true + }, + "scale": "interval", + "sourceField": "@timestamp" + }, + "823d0215-ee4e-4572-8a2a-e39893ece10d": { + "dataType": "ip", + "isBucketed": true, + "label": "Top values of client.ip", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "f14be824-7dc6-4399-8491-5777389b1f1c", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": false, + "size": 10, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "client.ip" + }, + "f14be824-7dc6-4399-8491-5777389b1f1c": { + "dataType": "number", + "isBucketed": false, + "label": "Count of records", + "operationType": "count", + "scale": "ratio", + "sourceField": "___records___" + } + }, + "incompleteColumns": {} + } + } + } + }, + "filters": [], + "query": { + "language": "kuery", + "query": "" + }, + "visualization": { + "axisTitlesVisibilitySettings": { + "x": true, + "yLeft": true, + "yRight": true + }, + "fittingFunction": "None", + "gridlinesVisibilitySettings": { + "x": true, + "yLeft": true, + "yRight": true + }, + "labelsOrientation": { + "x": 0, + "yLeft": 0, + "yRight": 0 + }, + "layers": [ + { + "accessors": [ + "f14be824-7dc6-4399-8491-5777389b1f1c" + ], + "layerId": "0ee62278-341b-4d9d-8f65-44eef424786b", + "layerType": "data", + "position": "top", + "seriesType": "line", + "showGridlines": false, + "splitAccessor": "823d0215-ee4e-4572-8a2a-e39893ece10d", + "xAccessor": "74ecbafb-fb61-4678-820e-e0cd221307f4" + } + ], + "legend": { + "isVisible": true, + "position": "right", + "legendSize": "auto" + }, + "preferredSeriesType": "line", + "tickLabelsVisibilitySettings": { + "x": true, + "yLeft": true, + "yRight": true + }, + "valueLabels": "hide", + "yLeftExtent": { + "mode": "full" + }, + "yRightExtent": { + "mode": "full" + } + } + }, + "title": "Top Client IP Trending Graph [Azure Frontdoor]", + "visualizationType": "lnsXY", + "references": [ + { + "id": "logs-*", + "name": "indexpattern-datasource-current-indexpattern", + "type": "index-pattern" + }, + { + "id": "logs-*", + "name": "indexpattern-datasource-layer-0ee62278-341b-4d9d-8f65-44eef424786b", + "type": "index-pattern" + } + ] + } + } + }, + { + "version": "8.6.0", + "type": "lens", + "gridData": { + "h": 17, + "i": "75629f82-636f-47f7-8080-b18e3e32fecf", + "w": 9, + "x": 0, + "y": 13 + }, + "panelIndex": "75629f82-636f-47f7-8080-b18e3e32fecf", + "embeddableConfig": { + "enhancements": {}, + "attributes": { + "description": "", + "state": { + "datasourceStates": { + "formBased": { + "layers": { + "dbf953f9-caf7-4403-aef3-0f888754526d": { + "columnOrder": [ + "7e7bf19e-0b03-49aa-b194-3ea5dc67f4c9", + "79b721f5-7a2e-4c74-9c8b-062b9b4d98db" + ], + "columns": { + "79b721f5-7a2e-4c74-9c8b-062b9b4d98db": { + "dataType": "number", + "isBucketed": false, + "label": "Count of records", + "operationType": "count", + "scale": "ratio", + "sourceField": "___records___" + }, + "7e7bf19e-0b03-49aa-b194-3ea5dc67f4c9": { + "dataType": "ip", + "isBucketed": true, + "label": "Top values of client.ip", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "79b721f5-7a2e-4c74-9c8b-062b9b4d98db", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": false, + "size": 10, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "client.ip" + } + }, + "incompleteColumns": {} + } + } + } + }, + "filters": [], + "query": { + "language": "kuery", + "query": "" + }, + "visualization": { + "columns": [ + { + "columnId": "7e7bf19e-0b03-49aa-b194-3ea5dc67f4c9" + }, + { + "columnId": "79b721f5-7a2e-4c74-9c8b-062b9b4d98db" + } + ], + "layerId": "dbf953f9-caf7-4403-aef3-0f888754526d", + "layerType": "data", + "rowHeight": "single", + "rowHeightLines": 1 + } + }, + "title": "Top Client IPs [Azure Frontdoor]", + "visualizationType": "lnsDatatable", + "references": [ + { + "id": "logs-*", + "name": "indexpattern-datasource-current-indexpattern", + "type": "index-pattern" + }, + { + "id": "logs-*", + "name": "indexpattern-datasource-layer-dbf953f9-caf7-4403-aef3-0f888754526d", + "type": "index-pattern" + } + ] + } + } + }, + { + "version": "8.6.0", + "type": "lens", + "gridData": { + "h": 17, + "i": "9d7f41e2-4835-49cd-97a8-3996b3803587", + "w": 17, + "x": 9, + "y": 13 + }, + "panelIndex": "9d7f41e2-4835-49cd-97a8-3996b3803587", + "embeddableConfig": { + "enhancements": {}, + "attributes": { + "description": "", + "state": { + "datasourceStates": { + "formBased": { + "layers": { + "b107299d-3122-4b2f-88c9-85b3e414217d": { + "columnOrder": [ + "f751542b-d8b3-486a-931c-545670d98874", + "a392968c-6481-4eba-8752-46420557d21f" + ], + "columns": { + "a392968c-6481-4eba-8752-46420557d21f": { + "dataType": "number", + "isBucketed": false, + "label": "Count of records", + "operationType": "count", + "scale": "ratio", + "sourceField": "___records___" + }, + "f751542b-d8b3-486a-931c-545670d98874": { + "dataType": "string", + "isBucketed": true, + "label": "Top values of source.geo.country_name", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "a392968c-6481-4eba-8752-46420557d21f", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": false, + "size": 10, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "source.geo.country_name" + } + }, + "incompleteColumns": {} + } + } + } + }, + "filters": [], + "query": { + "language": "kuery", + "query": "" + }, + "visualization": { + "layers": [ + { + "categoryDisplay": "default", + "layerId": "b107299d-3122-4b2f-88c9-85b3e414217d", + "layerType": "data", + "legendDisplay": "default", + "nestedLegend": false, + "numberDisplay": "percent", + "legendSize": "auto", + "primaryGroups": [ + "f751542b-d8b3-486a-931c-545670d98874" + ], + "metrics": [ + "a392968c-6481-4eba-8752-46420557d21f" + ] + } + ], + "palette": { + "name": "kibana_palette", + "type": "palette" + }, + "shape": "donut" + } + }, + "title": "Top Country Names [Azure Frontdoor]", + "visualizationType": "lnsPie", + "references": [ + { + "id": "logs-*", + "name": "indexpattern-datasource-current-indexpattern", + "type": "index-pattern" + }, + { + "id": "logs-*", + "name": "indexpattern-datasource-layer-b107299d-3122-4b2f-88c9-85b3e414217d", + "type": "index-pattern" + } + ] + } + } + }, + { + "version": "8.6.0", + "type": "lens", + "gridData": { + "h": 17, + "i": "a66e658f-88dd-4098-bc14-52775b5b32b5", + "w": 22, + "x": 26, + "y": 13 + }, + "panelIndex": "a66e658f-88dd-4098-bc14-52775b5b32b5", + "embeddableConfig": { + "enhancements": {}, + "attributes": { + "description": "", + "state": { + "datasourceStates": { + "formBased": { + "layers": { + "d889492f-07a3-4ec6-9334-7299e029d385": { + "columnOrder": [ + "08f47d60-115d-40f0-b9fd-9bf1385c766b", + "77477f59-4dba-4ec0-ada1-093ffc78374d" + ], + "columns": { + "08f47d60-115d-40f0-b9fd-9bf1385c766b": { + "dataType": "string", + "isBucketed": true, + "label": "Top values of url.original", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "77477f59-4dba-4ec0-ada1-093ffc78374d", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": false, + "size": 20, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "url.original" + }, + "77477f59-4dba-4ec0-ada1-093ffc78374d": { + "dataType": "number", + "isBucketed": false, + "label": "Count of records", + "operationType": "count", + "scale": "ratio", + "sourceField": "___records___" + } + }, + "incompleteColumns": {} + } + } + } + }, + "filters": [], + "query": { + "language": "kuery", + "query": "" + }, + "visualization": { + "columns": [ + { + "columnId": "08f47d60-115d-40f0-b9fd-9bf1385c766b" + }, + { + "columnId": "77477f59-4dba-4ec0-ada1-093ffc78374d" + } + ], + "layerId": "d889492f-07a3-4ec6-9334-7299e029d385", + "layerType": "data", + "rowHeight": "single", + "rowHeightLines": 1 + } + }, + "title": "Top URLs [Azure Frontdoor]", + "visualizationType": "lnsDatatable", + "references": [ + { + "id": "logs-*", + "name": "indexpattern-datasource-current-indexpattern", + "type": "index-pattern" + }, + { + "id": "logs-*", + "name": "indexpattern-datasource-layer-d889492f-07a3-4ec6-9334-7299e029d385", + "type": "index-pattern" + } + ] + } + } + }, + { + "version": "8.6.0", + "type": "lens", + "gridData": { + "h": 12, + "i": "408c25ae-832a-498f-88b1-c677a516195c", + "w": 17, + "x": 0, + "y": 30 + }, + "panelIndex": "408c25ae-832a-498f-88b1-c677a516195c", + "embeddableConfig": { + "enhancements": {}, + "attributes": { + "description": "", + "state": { + "datasourceStates": { + "formBased": { + "layers": { + "63bfc868-ae64-40f3-b7e1-62e2150f7704": { + "columnOrder": [ + "f629af01-d102-4903-9bbb-c7e80e525905", + "e1217af1-5b7b-4a1e-8b23-c2cca6cf8631", + "23695d1c-b544-4e27-9205-100f67392609" + ], + "columns": { + "23695d1c-b544-4e27-9205-100f67392609": { + "dataType": "number", + "isBucketed": false, + "label": "Count of records", + "operationType": "count", + "scale": "ratio", + "sourceField": "___records___" + }, + "e1217af1-5b7b-4a1e-8b23-c2cca6cf8631": { + "dataType": "string", + "isBucketed": true, + "label": "Top values of user_agent.os.name", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "23695d1c-b544-4e27-9205-100f67392609", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": false, + "size": 10, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "user_agent.os.name" + }, + "f629af01-d102-4903-9bbb-c7e80e525905": { + "dataType": "string", + "isBucketed": true, + "label": "Top values of user_agent.name", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "23695d1c-b544-4e27-9205-100f67392609", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": false, + "size": 10, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "user_agent.name" + } + }, + "incompleteColumns": {} + } + } + } + }, + "filters": [], + "query": { + "language": "kuery", + "query": "" + }, + "visualization": { + "layers": [ + { + "categoryDisplay": "default", + "layerId": "63bfc868-ae64-40f3-b7e1-62e2150f7704", + "layerType": "data", + "legendDisplay": "default", + "nestedLegend": false, + "numberDisplay": "percent", + "legendSize": "auto", + "primaryGroups": [ + "f629af01-d102-4903-9bbb-c7e80e525905", + "e1217af1-5b7b-4a1e-8b23-c2cca6cf8631" + ], + "metrics": [ + "23695d1c-b544-4e27-9205-100f67392609" + ] + } + ], + "palette": { + "name": "status", + "type": "palette" + }, + "shape": "donut" + } + }, + "title": "User Agents Names and OS Names [Azure Frontdoor]", + "visualizationType": "lnsPie", + "references": [ + { + "id": "logs-*", + "name": "indexpattern-datasource-current-indexpattern", + "type": "index-pattern" + }, + { + "id": "logs-*", + "name": "indexpattern-datasource-layer-63bfc868-ae64-40f3-b7e1-62e2150f7704", + "type": "index-pattern" + } + ] + } + } + }, + { + "version": "8.6.0", + "type": "lens", + "gridData": { + "h": 12, + "i": "95cf95ae-16c3-4787-a9ea-a401f6a0246f", + "w": 18, + "x": 17, + "y": 30 + }, + "panelIndex": "95cf95ae-16c3-4787-a9ea-a401f6a0246f", + "embeddableConfig": { + "enhancements": {}, + "attributes": { + "description": "", + "state": { + "datasourceStates": { + "formBased": { + "layers": { + "de5a74b1-0388-497f-b8ed-876c2c7c8e2e": { + "columnOrder": [ + "6b9235d9-4048-44b1-8285-d0867607799f", + "c006439b-bdfe-4054-972e-699fb00277d2" + ], + "columns": { + "6b9235d9-4048-44b1-8285-d0867607799f": { + "dataType": "string", + "isBucketed": true, + "label": "Top values of url.domain", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "c006439b-bdfe-4054-972e-699fb00277d2", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": false, + "size": 10, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "url.domain" + }, + "c006439b-bdfe-4054-972e-699fb00277d2": { + "dataType": "number", + "isBucketed": false, + "label": "Count of records", + "operationType": "count", + "scale": "ratio", + "sourceField": "___records___" + } + }, + "incompleteColumns": {} + } + } + } + }, + "filters": [], + "query": { + "language": "kuery", + "query": "" + }, + "visualization": { + "layers": [ + { + "categoryDisplay": "default", + "layerId": "de5a74b1-0388-497f-b8ed-876c2c7c8e2e", + "layerType": "data", + "legendDisplay": "default", + "nestedLegend": false, + "numberDisplay": "percent", + "legendSize": "auto", + "primaryGroups": [ + "6b9235d9-4048-44b1-8285-d0867607799f" + ], + "metrics": [ + "c006439b-bdfe-4054-972e-699fb00277d2" + ] + } + ], + "palette": { + "name": "temperature", + "type": "palette" + }, + "shape": "donut" + } + }, + "title": "Top WAF URL Domains [Azure Frontdoor]", + "visualizationType": "lnsPie", + "references": [ + { + "id": "logs-*", + "name": "indexpattern-datasource-current-indexpattern", + "type": "index-pattern" + }, + { + "id": "logs-*", + "name": "indexpattern-datasource-layer-de5a74b1-0388-497f-b8ed-876c2c7c8e2e", + "type": "index-pattern" + } + ] + } + } + }, + { + "version": "8.6.0", + "type": "lens", + "gridData": { + "h": 12, + "i": "0c6e0763-18cd-4360-aede-b92d09e7a2c6", + "w": 13, + "x": 35, + "y": 30 + }, + "panelIndex": "0c6e0763-18cd-4360-aede-b92d09e7a2c6", + "embeddableConfig": { + "enhancements": {}, + "attributes": { + "description": "", + "state": { + "datasourceStates": { + "formBased": { + "layers": { + "15580362-caea-4ea9-85ba-7583ab86c799": { + "columnOrder": [ + "d6ceac1c-38fa-4025-a94a-f6f2001ff848", + "61b5338d-8241-4b3b-8e82-193b301068ca" + ], + "columns": { + "61b5338d-8241-4b3b-8e82-193b301068ca": { + "dataType": "number", + "isBucketed": false, + "label": "Count of records", + "operationType": "count", + "scale": "ratio", + "sourceField": "___records___" + }, + "d6ceac1c-38fa-4025-a94a-f6f2001ff848": { + "dataType": "string", + "isBucketed": true, + "label": "Top values of event.action", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "61b5338d-8241-4b3b-8e82-193b301068ca", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": true, + "size": 10, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "event.action" + } + }, + "incompleteColumns": {} + } + } + } + }, + "filters": [], + "query": { + "language": "kuery", + "query": "" + }, + "visualization": { + "layers": [ + { + "categoryDisplay": "default", + "layerId": "15580362-caea-4ea9-85ba-7583ab86c799", + "layerType": "data", + "legendDisplay": "default", + "nestedLegend": false, + "numberDisplay": "percent", + "legendSize": "auto", + "primaryGroups": [ + "d6ceac1c-38fa-4025-a94a-f6f2001ff848" + ], + "metrics": [ + "61b5338d-8241-4b3b-8e82-193b301068ca" + ] + } + ], + "palette": { + "name": "status", + "type": "palette" + }, + "shape": "pie" + } + }, + "title": "WAF Event Actions [Azure Frontdoor]", + "visualizationType": "lnsPie", + "references": [ + { + "id": "logs-*", + "name": "indexpattern-datasource-current-indexpattern", + "type": "index-pattern" + }, + { + "id": "logs-*", + "name": "indexpattern-datasource-layer-15580362-caea-4ea9-85ba-7583ab86c799", + "type": "index-pattern" + } + ] + } + } + }, + { + "version": "8.6.0", + "type": "lens", + "gridData": { + "h": 15, + "i": "a7777948-86d7-42e0-9463-032b402385f9", + "w": 24, + "x": 0, + "y": 42 + }, + "panelIndex": "a7777948-86d7-42e0-9463-032b402385f9", + "embeddableConfig": { + "enhancements": {}, + "attributes": { + "description": "", + "state": { + "datasourceStates": { + "formBased": { + "layers": { + "bcd2b4e0-0ffe-4901-9588-9687fc86a3f9": { + "columnOrder": [ + "423ae552-3c4e-49db-87b6-eb5802c317c3", + "97038146-0485-4c93-ad56-e815957ef6a0" + ], + "columns": { + "423ae552-3c4e-49db-87b6-eb5802c317c3": { + "dataType": "string", + "isBucketed": true, + "label": "Top values of rule.name", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "97038146-0485-4c93-ad56-e815957ef6a0", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": false, + "size": 10, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "rule.name" + }, + "97038146-0485-4c93-ad56-e815957ef6a0": { + "dataType": "number", + "isBucketed": false, + "label": "Count of records", + "operationType": "count", + "scale": "ratio", + "sourceField": "___records___" + } + }, + "incompleteColumns": {} + } + } + } + }, + "filters": [], + "query": { + "language": "kuery", + "query": "" + }, + "visualization": { + "columns": [ + { + "columnId": "423ae552-3c4e-49db-87b6-eb5802c317c3" + }, + { + "columnId": "97038146-0485-4c93-ad56-e815957ef6a0" + } + ], + "layerId": "bcd2b4e0-0ffe-4901-9588-9687fc86a3f9", + "layerType": "data", + "rowHeight": "single", + "rowHeightLines": 1 + } + }, + "title": "Top WAF Rule Names [Azure Frontdoor]", + "visualizationType": "lnsDatatable", + "references": [ + { + "id": "logs-*", + "name": "indexpattern-datasource-current-indexpattern", + "type": "index-pattern" + }, + { + "id": "logs-*", + "name": "indexpattern-datasource-layer-bcd2b4e0-0ffe-4901-9588-9687fc86a3f9", + "type": "index-pattern" + } + ] + } + } + }, + { + "version": "8.6.0", + "type": "lens", + "gridData": { + "h": 15, + "i": "aa73e953-7e0a-4f4b-a069-fe1cedd2c53f", + "w": 24, + "x": 24, + "y": 42 + }, + "panelIndex": "aa73e953-7e0a-4f4b-a069-fe1cedd2c53f", + "embeddableConfig": { + "enhancements": {}, + "attributes": { + "description": "", + "state": { + "datasourceStates": { + "formBased": { + "layers": { + "b136b727-78fc-4467-ae19-7284f19d1e8e": { + "columnOrder": [ + "c0164b02-0ae2-4c90-b5b8-9b2da03aa6ac", + "9de17676-7ef0-4ff8-a6a1-52df55f74b6f" + ], + "columns": { + "9de17676-7ef0-4ff8-a6a1-52df55f74b6f": { + "dataType": "number", + "isBucketed": false, + "label": "Count of records", + "operationType": "count", + "scale": "ratio", + "sourceField": "___records___" + }, + "c0164b02-0ae2-4c90-b5b8-9b2da03aa6ac": { + "dataType": "string", + "isBucketed": true, + "label": "Top values of azure.frontdoor.waf.details.msg", + "operationType": "terms", + "params": { + "missingBucket": false, + "orderBy": { + "columnId": "9de17676-7ef0-4ff8-a6a1-52df55f74b6f", + "type": "column" + }, + "orderDirection": "desc", + "otherBucket": false, + "size": 10, + "parentFormat": { + "id": "terms" + } + }, + "scale": "ordinal", + "sourceField": "azure.frontdoor.waf.details.msg" + } + }, + "incompleteColumns": {} + } + } + } + }, + "filters": [], + "query": { + "language": "kuery", + "query": "" + }, + "visualization": { + "columns": [ + { + "columnId": "c0164b02-0ae2-4c90-b5b8-9b2da03aa6ac" + }, + { + "columnId": "9de17676-7ef0-4ff8-a6a1-52df55f74b6f" + } + ], + "layerId": "b136b727-78fc-4467-ae19-7284f19d1e8e", + "layerType": "data", + "rowHeight": "single", + "rowHeightLines": 1 + } + }, + "title": "Top WAF Detail Msg [Azure Frontdoor]", + "visualizationType": "lnsDatatable", + "references": [ + { + "id": "logs-*", + "name": "indexpattern-datasource-current-indexpattern", + "type": "index-pattern" + }, + { + "id": "logs-*", + "name": "indexpattern-datasource-layer-b136b727-78fc-4467-ae19-7284f19d1e8e", + "type": "index-pattern" + } + ] + } + } + } + ], + "timeRestore": false, + "title": "[Azure Frontdoor] Overview", + "version": 1 + }, + "references": [ + { + "id": "logs-*", + "name": "kibanaSavedObjectMeta.searchSourceJSON.filter[0].meta.index", + "type": "index-pattern" + }, + { + "type": "index-pattern", + "name": "f8012579-e741-44fc-9470-5348fa7a6821:indexpattern-datasource-current-indexpattern", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "f8012579-e741-44fc-9470-5348fa7a6821:indexpattern-datasource-layer-266caf24-daea-453b-a081-b81a3a1a5d34", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "a318c8ca-32a6-4115-81c2-7448d02f30c1:indexpattern-datasource-current-indexpattern", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "a318c8ca-32a6-4115-81c2-7448d02f30c1:indexpattern-datasource-layer-0ee62278-341b-4d9d-8f65-44eef424786b", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "75629f82-636f-47f7-8080-b18e3e32fecf:indexpattern-datasource-current-indexpattern", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "75629f82-636f-47f7-8080-b18e3e32fecf:indexpattern-datasource-layer-dbf953f9-caf7-4403-aef3-0f888754526d", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "9d7f41e2-4835-49cd-97a8-3996b3803587:indexpattern-datasource-current-indexpattern", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "9d7f41e2-4835-49cd-97a8-3996b3803587:indexpattern-datasource-layer-b107299d-3122-4b2f-88c9-85b3e414217d", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "a66e658f-88dd-4098-bc14-52775b5b32b5:indexpattern-datasource-current-indexpattern", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "a66e658f-88dd-4098-bc14-52775b5b32b5:indexpattern-datasource-layer-d889492f-07a3-4ec6-9334-7299e029d385", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "408c25ae-832a-498f-88b1-c677a516195c:indexpattern-datasource-current-indexpattern", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "408c25ae-832a-498f-88b1-c677a516195c:indexpattern-datasource-layer-63bfc868-ae64-40f3-b7e1-62e2150f7704", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "95cf95ae-16c3-4787-a9ea-a401f6a0246f:indexpattern-datasource-current-indexpattern", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "95cf95ae-16c3-4787-a9ea-a401f6a0246f:indexpattern-datasource-layer-de5a74b1-0388-497f-b8ed-876c2c7c8e2e", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "0c6e0763-18cd-4360-aede-b92d09e7a2c6:indexpattern-datasource-current-indexpattern", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "0c6e0763-18cd-4360-aede-b92d09e7a2c6:indexpattern-datasource-layer-15580362-caea-4ea9-85ba-7583ab86c799", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "a7777948-86d7-42e0-9463-032b402385f9:indexpattern-datasource-current-indexpattern", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "a7777948-86d7-42e0-9463-032b402385f9:indexpattern-datasource-layer-bcd2b4e0-0ffe-4901-9588-9687fc86a3f9", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "aa73e953-7e0a-4f4b-a069-fe1cedd2c53f:indexpattern-datasource-current-indexpattern", + "id": "logs-*" + }, + { + "type": "index-pattern", + "name": "aa73e953-7e0a-4f4b-a069-fe1cedd2c53f:indexpattern-datasource-layer-b136b727-78fc-4467-ae19-7284f19d1e8e", + "id": "logs-*" + } + ], + "migrationVersion": { + "dashboard": "8.6.0" + }, + "coreMigrationVersion": "8.6.0" +} \ No newline at end of file diff --git a/packages/azure_frontdoor/manifest.yml b/packages/azure_frontdoor/manifest.yml new file mode 100644 index 00000000000..af6f4a90481 --- /dev/null +++ b/packages/azure_frontdoor/manifest.yml @@ -0,0 +1,73 @@ +format_version: 1.0.0 +name: azure_frontdoor +title: "Azure Frontdoor" +version: 0.0.1 +license: basic +description: "This Elastic integration collects logs from Azure Frontdoor." +type: integration +categories: + - azure + - network + - security + - web +release: experimental +conditions: + kibana.version: "^8.6.0" +screenshots: + - src: /img/azure-frontdoor-overview.png + title: Azure Frontdoor Overview + size: 600x600 + type: image/png +icons: + - src: /img/front-door.svg + title: Frontdoor logo + size: 32x32 + type: image/svg+xml +policy_templates: + - name: azure_frontdoor + title: Azure Frontdoor logs + description: Collect sample logs + inputs: + - type: "azure-eventhub" + title: "Collect azure frontdoor events from Event Hub" + description: "Collecting azure frontdooor events from Azure eventhub inputs (input: azure-eventhub)." + vars: + - name: eventhub + type: text + title: Eventhub + multi: false + required: true + show_user: true + - name: consumer_group + type: text + title: Consumer Group + multi: false + required: true + show_user: true + default: $Default + - name: connection_string + type: text + title: Connection String + multi: false + required: true + show_user: true + - name: storage_account + type: text + title: Storage Account + multi: false + required: true + show_user: true + - name: storage_account_key + type: text + title: Storage Account Key + multi: false + required: true + show_user: true + - name: resource_manager_endpoint + type: text + title: Resource Manager Endpoint + multi: false + required: false + show_user: true +owner: + github: elastic/security-external-integrations