Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.
https://azure.microsoft.com/en-us/services/azure-sentinel/
MIT License
4.62k stars 3.03k forks source link

Ubiquiti Solution Doesn't Use Custom Logs via AMA #11423

Open doodlemania2 opened 1 week ago

doodlemania2 commented 1 week ago

Describe the bug The solution says Custom Log via AMA is required, however, so I set that up. However, the solution itself still wants to use the now deprecated connector when running reports or queries.

To Reproduce Steps to reproduce the behavior:

  1. Install AMA, configure log ingestion from Unifi's SNMP trap on premise. Logs flowing into Sentinel's Log Analytics Ubiquiti_CL
  2. Install solution
  3. Do not configure the deprecated connector
  4. No results are being found

Expected behavior Results in Hunting, Logs, etc produce

v-sudkharat commented 1 week ago

Hi @doodlemania2, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates. Thanks!

v-sudkharat commented 4 days ago

@doodlemania2, Could you please let us know which solution version you are using? And please also know what error you're facing while configuring the rule or running the Parser. Thanks!

doodlemania2 commented 4 days ago

Hi there, here's the version info: Image which creates two connectors - the deprecated one and the AMA one: Image I set up the AMA log and logs are flowing: Image but the workbooks and other components are (at least appear) to still be looking for data from the deprecated connector: Image -- isn't configured because deprecated Image

v-sudkharat commented 1 day ago

@doodlemania2, Thanks for the sharing detailed info. we will check into the issue and get back to you. And could you please share the Ubiquiti_CL logs with us in below mail id - v-sudkharat@microsoft.com

Thanks!