{
  "id": "BlackberryCylancePROTECT",
  "title": "[Deprecated] Blackberry CylancePROTECT",
  "publisher": "Blackberry",
  "descriptionMarkdown": "The [Blackberry CylancePROTECT](https://www.blackberry.com/us/en/products/blackberry-protect) connector allows you to easily connect your CylancePROTECT logs with Microsoft Sentinel. This gives you more insight into your organization's network and improves your security operation capabilities.",
  "additionalRequirementBanner": "These queries are dependent on a parser based on a Kusto Function deployed as part of the solution.",
  "graphQueries": [
    {
      "metricName": "Total data received",
      "legend": "CylancePROTECT",
      "baseQuery": "CylancePROTECT​"
    }
  ],
  "sampleQueries": [
    {
      "description": "Top 10 Event Types",
      "query": "CylancePROTECT​\n            | summarize count() by EventName\n            | top 10 by count_"
    },
    {
      "description": "Top 10 Triggered Policies",
      "query": "CylancePROTECT​\n            | where EventType == \"Threat\" \n            | summarize count() by PolicyName \n            | top 10 by count_"
    }
  ],
  "connectivityCriterias": [
    {
      "type": "IsConnectedQuery",
      "value": [
        "CylancePROTECT​\n |where TimeGenerated > ago(3d)\n    |take 1\n   | project IsConnected = true"
      ]
    }
  ],
  "dataTypes": [
    {
      "name": "Syslog (CylancePROTECT)",
      "lastDataReceivedQuery": "CylancePROTECT​\n            | summarize Time = max(TimeGenerated)\n            | where isnotempty(Time)"
    }
  ],
  "availability": {
    "status": 1,
    "isPreview": false
  },
  "permissions": {
    "resourceProvider": [
      {
        "provider": "Microsoft.OperationalInsights/workspaces",
        "permissionsDisplayText": "write permission.",
        "providerDisplayName": "Workspace",
        "scope": "Workspace",
        "requiredPermissions": { "write": true, "delete": true }
      }
    ],
    "customs": [
      {
        "name": "CylancePROTECT",
        "description": "must be configured to export logs via Syslog."
      }
    ]
  },
  "instructionSteps": [
    {
      "description": ">**NOTE:** This data connector depends on a parser based on a Kusto Function to work as expected which is deployed as part of the solution. To view the function code in Log Analytics, open Log Analytics/Microsoft Sentinel Logs blade, click Functions and search for the alias CyclanePROTECT and load the function code or click [here](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Blackberry%20CylancePROTECT/Parsers/CylancePROTECT.txt), on the second line of the query, enter the hostname(s) of your CyclanePROTECT device(s) and any other unique identifiers for the logstream. The function usually takes 10-15 minutes to activate after solution installation/update."
    },
    {
      "title": "1. Install and onboard the agent for Linux",
      "description": "Typically, you should install the agent on a different computer from the one on which the logs are generated.\n\n>  Syslog logs are collected only from **Linux** agents.",
      "instructions": [
        {
          "parameters": {
            "title": "Choose where to install the agent:",
            "instructionSteps": [
              {
                "title": "Install agent on Azure Linux Virtual Machine",
                "description": "Select the machine to install the agent on and then click **Connect**.",
                "instructions": [
                  {
                    "parameters": {
                      "linkType": "InstallAgentOnLinuxVirtualMachine"
                    },
                    "type": "InstallAgent"
                  }
                ]
              },
              {
                "title": "Install agent on a non-Azure Linux Machine",
                "description": "Download the agent on the relevant machine and follow the instructions.",
                "instructions": [
                  {
                    "parameters": { "linkType": "InstallAgentOnLinuxNonAzure" },
                    "type": "InstallAgent"
                  }
                ]
              }
            ]
          },
          "type": "InstructionStepsGroup"
        }
      ]
    },
    {
      "title": "2. Configure the logs to be collected",
      "description": "Configure the facilities you want to collect and their severities.\n\n1.  Select the link below to open your workspace **agents configuration**, and select the **Syslog** tab.\n2.  Select **Add facility** and choose from the drop-down list of facilities. Repeat for all the facilities you want to add.\n3.  Mark the check boxes for the desired severities for each facility.\n4.  Click **Apply**.",
      "instructions": [
        {
          "parameters": { "linkType": "OpenSyslogSettings" },
          "type": "InstallAgent"
        }
      ]
    },
    {
      "title": "3. Configure and connect the CylancePROTECT",
      "description": "[Follow these instructions](https://docs.blackberry.com/content/dam/docs-blackberry-com/release-pdfs/en/cylance-products/syslog-guides/Cylance%20Syslog%20Guide%20v2.0%20rev12.pdf) to configure the CylancePROTECT to forward syslog. Use the IP address or hostname for the Linux device with the Linux agent installed as the Destination IP address."
    }
  ]
}
