Skip to content

Commit

Permalink
Fix warnings
Browse files Browse the repository at this point in the history
  • Loading branch information
Saisang committed Oct 23, 2024
1 parent 73258c2 commit 6f285bb
Show file tree
Hide file tree
Showing 7 changed files with 25 additions and 38 deletions.
36 changes: 18 additions & 18 deletions articles/sentinel/data-connectors/armis-alerts-activities.md
Original file line number Diff line number Diff line change
Expand Up @@ -91,15 +91,15 @@ Use this method for automated deployment of the Armis connector.
[![Deploy To Azure](https://aka.ms/deploytoazurebutton)](https://aka.ms/sentinel-ArmisAlertsActivitiesAPI-azuredeploy) [![Deploy to Azure Gov](https://aka.ms/deploytoazuregovbutton)](https://aka.ms/sentinel-ArmisAlertsActivitiesAPI-azuredeploy-gov)
2. Select the preferred **Subscription**, **Resource Group** and **Location**.
3. Enter the below information :
Function Name
Workspace ID
Workspace Key
Armis Secret Key
Armis URL (https://<armis-instance>.armis.com/api/v1/)
Armis Alert Table Name
Armis Activity Table Name
Armis Schedule
Avoid Duplicates (Default: true)
- Function Name
- Workspace ID
- Workspace Key
- Armis Secret Key
- Armis URL `https://<armis-instance>.armis.com/api/v1/`
- Armis Alert Table Name
- Armis Activity Table Name
- Armis Schedule
- Avoid Duplicates (Default: true)
4. Mark the checkbox labeled **I agree to the terms and conditions stated above**.
5. Click **Purchase** to deploy.

Expand Down Expand Up @@ -141,15 +141,15 @@ If you're already signed in, go to the next step.
1. In the Function App, select the Function App Name and select **Configuration**.
2. In the **Application settings** tab, select **+ New application setting**.
3. Add each of the following application settings individually, with their respective values (case-sensitive):
Workspace ID
Workspace Key
Armis Secret Key
Armis URL (https://<armis-instance>.armis.com/api/v1/)
Armis Alert Table Name
Armis Activity Table Name
Armis Schedule
Avoid Duplicates (Default: true)
logAnalyticsUri (optional)
- Workspace ID
- Workspace Key
- Armis Secret Key
- Armis URL `https://<armis-instance>.armis.com/api/v1/`
- Armis Alert Table Name
- Armis Activity Table Name
- Armis Schedule
- Avoid Duplicates (Default: true)
- logAnalyticsUri (optional)
- Use logAnalyticsUri to override the log analytics API endpoint for dedicated cloud. For example, for public cloud, leave the value empty; for Azure GovUS cloud environment, specify the value in the following format: `https://<CustomerId>.ods.opinsights.azure.us`.
4. Once all application settings have been entered, click **Save**.

Expand Down
4 changes: 2 additions & 2 deletions articles/sentinel/data-connectors/armorblox.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ ms.collection: sentinel-data-connector

# Armorblox (using Azure Functions) connector for Microsoft Sentinel

The [Armorblox](https://www.armorblox.com/) data connector provides the capability to ingest incidents from your Armorblox instance into Microsoft Sentinel through the REST API. The connector provides ability to get events which helps to examine potential security risks, and more.
The Armorblox data connector provides the capability to ingest incidents from your Armorblox instance into Microsoft Sentinel through the REST API. The connector provides ability to get events which helps to examine potential security risks, and more.

This is autogenerated content. For changes, contact the solution provider.

Expand All @@ -23,7 +23,7 @@ This is autogenerated content. For changes, contact the solution provider.
| **Azure function app code** | https://aka.ms/sentinel-armorblox-functionapp |
| **Log Analytics table(s)** | Armorblox_CL<br/> |
| **Data collection rules support** | Not currently supported |
| **Supported by** | [Armorblox](https://www.armorblox.com/contact/) |
| **Supported by** | Armorblox |

## Query samples

Expand Down
4 changes: 2 additions & 2 deletions articles/sentinel/data-connectors/illumio-saas.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ Illumio_Flow_Events_CL
To integrate with Illumio SaaS (using Azure Functions) make sure you have:

- **Microsoft.Web/sites permissions**: Read and write permissions to Azure Functions to create a Function App is required. [See the documentation to learn more about Azure Functions](/azure/azure-functions/).
- **SQS and AWS S3 account credentials/permissions**: **AWS_SECRET**, **AWS_REGION_NAME**, **AWS_KEY**, **QUEUE_URL** is required. [See the documentation to learn more about data pulling](<Replace with an entry to documentation>). If you are using s3 bucket provided by Illumio, contact Illumio support. At your request they will provide you with the AWS S3 bucket name, AWS SQS url and AWS credentials to access them.
- **SQS and AWS S3 account credentials/permissions**: **AWS_SECRET**, **AWS_REGION_NAME**, **AWS_KEY**, **QUEUE_URL** is required. See the documentation to learn more about data pulling. If you are using s3 bucket provided by Illumio, contact Illumio support. At your request they will provide you with the AWS S3 bucket name, AWS SQS url and AWS credentials to access them.
- **Illumio API key and secret**: **ILLUMIO_API_KEY**, **ILLUMIO_API_SECRET** is required for a workbook to make connection to SaaS PCE and fetch api responses.


Expand Down Expand Up @@ -111,7 +111,7 @@ Deployment via Visual Studio Code.

**2. Configure the Function App**

1. Follow documentation <insert link> to set up all required environment variables and click **Save**. Ensure you restart the function app once settings are saved.
1. Follow documentation to set up all required environment variables and click **Save**. Ensure you restart the function app once settings are saved.



Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ This is autogenerated content. For changes, contact the solution provider.

| Connector attribute | Description |
| --- | --- |
| **Log Analytics table(s)** | Failed_Range_To_Ingest_CL<br/> Infoblox_Failed_Indicators_CL<br/> dossier_whois_CL<br/> dossier_whitelist_CL<br/> dossier_tld_risk_CL<br/> dossier_threat_actor_CL<br/> dossier_rpz_feeds_records_CL<br/> dossier_rpz_feeds_CL<br/> dossier_nameserver_matches_CL<br/> dossier_nameserver_CL<br/> dossier_malware_analysis_v3_CL<br/> dossier_inforank_CL<br/> dossier_infoblox_web_cat_CL<br/> dossier_geo_CL<br/> dossier_dns_CL<br/> dossier_atp_threat_CL<br/> dossier_atp_CL<br/> dossier_ptr_CL<br/> |
| **Log Analytics table(s)** | Failed_Range_To_Ingest_CL<br/> Infoblox_Failed_Indicators_CL<br/> dossier_whois_CL<br/> dossier_tld_risk_CL<br/> dossier_threat_actor_CL<br/> dossier_rpz_feeds_records_CL<br/> dossier_rpz_feeds_CL<br/> dossier_nameserver_matches_CL<br/> dossier_nameserver_CL<br/> dossier_malware_analysis_v3_CL<br/> dossier_inforank_CL<br/> dossier_infoblox_web_cat_CL<br/> dossier_geo_CL<br/> dossier_dns_CL<br/> dossier_atp_threat_CL<br/> dossier_atp_CL<br/> dossier_ptr_CL<br/> |
| **Data collection rules support** | Not currently supported |
| **Supported by** | [Infoblox](https://support.infoblox.com/) |

Expand Down Expand Up @@ -49,14 +49,6 @@ dossier_whois_CL
| sort by TimeGenerated desc
```

**Dossier whitelist data source**

```kusto
dossier_whitelist_CL
| sort by TimeGenerated desc
```

**Dossier tld risk data source**

```kusto
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ You can send indicators by calling our Upload Indicators API. For more informati

>HTTP method: POST
>Endpoint: https://api.ti.sentinel.azure.com/workspaces/[WorkspaceID]/threatintelligenceindicators:upload?api-version=2022-07-01
>Endpoint: `https://api.ti.sentinel.azure.com/workspaces/[WorkspaceID]/threatintelligenceindicators:upload?api-version=2022-07-01`
>WorkspaceID: the workspace that the indicators are uploaded to.
Expand Down
2 changes: 1 addition & 1 deletion articles/sentinel/data-connectors/zerofox-cti.md
Original file line number Diff line number Diff line change
Expand Up @@ -74,7 +74,7 @@ To integrate with ZeroFox CTI (using Azure Functions) make sure you have:
Follow these instructions for set up logging and obtain credentials.
1. [Log into ZeroFox's website.](https://cloud.zerofox.com/login) using your username and password
2 - Click into the Settings button and go to the Data Connectors Section.
3 - Select the API DATA FEEDS tab and head to the bottom of the page, select <<Reset>> in the API Information box, to obtain a Personal Access Token to be used along with your username.
3 - Select the API DATA FEEDS tab and head to the bottom of the page, select **Reset** in the API Information box, to obtain a Personal Access Token to be used along with your username.


**STEP 2 - Deploy the Azure Function data connectors using the Azure Resource Manager template: **
Expand Down
5 changes: 0 additions & 5 deletions redirects/.openpublishing.redirection.sentinel.json
Original file line number Diff line number Diff line change
Expand Up @@ -1650,11 +1650,6 @@
"redirect_url": "/azure/sentinel/data-connectors-reference",
"redirect_document_id": false
},
{
"source_path_from_root": "/articles/sentinel/data-connectors/hyas-protect.md",
"redirect_url": "/azure/sentinel/data-connectors-reference",
"redirect_document_id": false
},
{
"source_path_from_root": "/articles/sentinel/data-connectors/security-events-via-legacy-agent.md",
"redirect_url": "/previous-versions/azure/sentinel/data-connectors/security-events-via-legacy-agent",
Expand Down

0 comments on commit 6f285bb

Please sign in to comment.