{
    "Name": "Cisco SD-WAN",
    "Author": "Cisco Systems - support@cisco.com",
    "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/cisco-logo-72px.svg\" width=\"75px\" height=\"75px\">",
    "Description": "The [Cisco SD-WAN](https://www.cisco.com/c/en_in/solutions/enterprise-networks/sd-wan/index.html) solution for Microsoft Sentinel enables you to ingest Syslog and Netflow logs into Microsoft Sentinel, providing insight into network threats and vulnerabilities.\r\n \r\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\na. [Agent-based log collection (Syslog) ](https://learn.microsoft.com/azure/sentinel/forward-syslog-monitor-agent)",
    "Analytic Rules": [
        "Analytic Rules/CiscoSDWANSentinelIntrusionEvents.yaml",
        "Analytic Rules/CiscoSDWANSentinelIPSEventThreshold.yaml",
        "Analytic Rules/CiscoSDWANSentinelMalwareEvents.yaml",
        "Analytic Rules/CiscoSDWANSentinelMonitorCriticalIP.yaml"
    ],
    "Playbooks": [
        "Playbooks/CiscoSDWANIntrusionLogicAPP/azuredeploy.json",
        "Playbooks/CiscoSDWANLogicAPP/azuredeploy.json",
        "Playbooks/CiscoSDWANReport/azuredeploy.json"
    ],
    "Workbooks": [
        "Workbooks/CiscoSDWAN.json"
    ],
    "Data Connectors": [
        "Data Connectors/CiscoSDWAN.json"
    ],
    "Parsers": [
        "Parsers/CiscoSDWANNetflow.txt",
        "Parsers/CiscoSyslogFW6LogSummary.txt",
        "Parsers/CiscoSyslogUTD.txt",
        "Parsers/MapNetflowUsername.txt"
    ],
    "BasePath": "C:\\Azure-Sentinel\\Solutions\\Cisco SD-WAN",
    "Version": "2.0.0",
    "Metadata": "SolutionMetadata.json",
    "TemplateSpec": true,
    "Is1PConnector": false
}