Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.
https://azure.microsoft.com/en-us/services/azure-sentinel/
MIT License
4.58k stars 3.01k forks source link

Setting up a new custom connector for security solution #474

Closed utsavpatel51 closed 4 years ago

utsavpatel51 commented 4 years ago

I am developing a new connector on top of a built-in connector(Common Event Format(CEF)) just like Checkpoint,CISCO ASA, for which a security solution is yet to develop.I am not getting proper guidelines/documentation on how to add setup/add a new vendor (as a security solution) to configure with my custom connector(in-built CEF connector in my case).We can create workbook and PR it but if we want to create new data connector for new security solution which has CEF format data how can we create data connector for that?

shainw commented 4 years ago

@utsavpatel51 - Does this help you - https://techcommunity.microsoft.com/t5/azure-sentinel/azure-sentinel-creating-custom-connectors/ba-p/864060

utsavpatel51 commented 4 years ago

@shainw - currently azure sentinel have 33 data connector image how can I add my own security vendor connector? I have created logic app connector but how can i publish it to azure so everyone can use it?

oshezaf commented 4 years ago

Hi @utsavpatel51 : at this point to be included in the connector gallery, you will have to work with our technical partnership team. Contact me privately so I can put you in contact with them.

utsavpatel51 commented 4 years ago

Are you talking about the Contributor License Agreement (CLA) or another thing?

shainw commented 4 years ago

@utsavpatel51 - were you able to connect up with Ofer?

oshezaf commented 4 years ago

@utsavpatel51 : I am not referring to the CLA. The technical partnership team would be able to guide you as to the requirements for inclusion.

utsavpatel51 commented 4 years ago

Hi @utsavpatel51 : at this point to be included in the connector gallery, you will have to work with our technical partnership team. Contact me privately so I can put you in contact with them.

Hi @oshezaf : Can you share your contact details please or if you can connect me directly to the technical partnership team, anything would be a great help!

oshezaf commented 4 years ago

Hi @oshezaf : Can you share your contact details please or if you can connect me directly to the technical partnership team, anything would be a great help!

Send me an e-mail to ofer dot shezaf at microsoft dot com

dicolanl commented 4 years ago

@oshezaf can we close this since it was taken offline?

shainw commented 4 years ago

I say so, closing for now and we can re-open if needed. :)

shikhin-metron commented 3 years ago

Hi, I also want to add my own connector in the connectors gallery. My question is, is there any way we can test the solution by connecting, how it would work in the gallery before actually getting it into connector gallery? I am using log analytics api with azure functions.

shikhin-metron commented 3 years ago

Hi, I also want to add my own connector in the connectors gallery. My question is, is there any way we can test the solution by connecting, how it would work in the gallery before actually getting it into connector gallery? I am using log analytics api with azure functions.

@oshezaf @shainw can you guys help me with this?

oshezaf commented 3 years ago

We are in private preview for such a feature. Are you a member of the Azure Security private preview ring?

Tagging @shikhin-metron