Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.
https://azure.microsoft.com/en-us/services/azure-sentinel/
MIT License
4.37k stars 2.89k forks source link

Update Connector_Syslog_CiscoMeraki.json to include firewall logs #10718

Closed tduarte14 closed 1 hour ago

tduarte14 commented 5 days ago

In Firmware MX18.101 and newer, the syslog messages for "flows" has been changed to "firewall", "vpn_firewall", "cellular_firewall" or "bridge_anyconnect_client_vpn_firewall" depending on which rule was matched, so added firewall filter to the instructions.

Required items, please complete

Change(s):

v-atulyadav commented 5 days ago

Hi @tduarte14, Please repackage this solution using v3 tool. Thanks

tduarte14 commented 2 hours ago

Hi @v-atulyadav why does this need to be repackaged that way? I'm already wasting my time sharing a fix for something that is not properly done and you want to give me more work on my side?

v-atulyadav commented 2 hours ago

Hi @tduarte14, Any change made in the connector file does not appear in the solution unless it is repackaged. I understand and appreciate your efforts towards this fix. We will repackage this solution and raise a PR for it. Thanks