{
    "id": "OneIdentity",
    "title": "One Identity Safeguard",
    "publisher": "One Identity LLC.",
    "logo": "OneIdentityCloud.svg",
    "descriptionMarkdown": "The One Identity Safeguard (CEF) Sentinel data connector enhances the standard Common Event Format (CEF) connector with Safeguard for Privileged Sessions-specific dashboards. Use this connector to easily start utilizing the events generated by your device for visualization, alerts, investigations and more.",
    "graphQueries": [
        {
            "metricName": "Total data received",
            "legend": "One Identity LLC.",
            "baseQuery": "\nCommonSecurityLog\n| where DeviceVendor == \"OneIdentity\" and DeviceProduct == \"SPS\"\n"
        }
    ],
    "sampleQueries": [
        {
            "description": "All logs of the last 24 hours",
            "query": "\nCommonSecurityLog\n| where DeviceVendor == \"OneIdentity\" and DeviceProduct == \"SPS\"\n\n            | where TimeGenerated > ago(1d) \n                | sort by TimeGenerated desc"
        },
        {
            "description": "Safeguard for Privileged Sessions session count of the last 24 hours",
            "query": "\nCommonSecurityLog\n| where DeviceVendor == \"OneIdentity\" and DeviceProduct == \"SPS\"\n\n            | where TimeGenerated > ago(1d) \n                | where DeviceCustomString1Label == \"Session ID\"\n                | summarize any(*) by DeviceCustomString1\n                | count"
        },
        {
            "description": "Safeguard for Privileged Sessions session count by verdict (ACCEPT/DENY/AUTH_FAIL)",
            "query": "\nCommonSecurityLog\n| where DeviceVendor == \"OneIdentity\" and DeviceProduct == \"SPS\"\n\n            | where TimeGenerated > ago(1d)\n            | where Activity == \"SessionClosed\"\n            | summarize count() by DeviceCustomString2"
        },
        {
            "description": "Safeguard for Privileged Sessions session count by severity (if analytics is enabled)",
            "query": "\nCommonSecurityLog\n| where DeviceVendor == \"OneIdentity\" and DeviceProduct == \"SPS\"\n\n            | where TimeGenerated > ago(1d)\n            | where DeviceCustomString1Label == \"Session ID\"\n            | summarize max(LogSeverity) by DeviceCustomString1\n            | summarize count() by max_LogSeverity"
        }
    ],
    "connectivityCriterias": [
        {
            "type": "IsConnectedQuery",
            "value": [
                "\nCommonSecurityLog\n| where DeviceVendor == \"OneIdentity\" and DeviceProduct == \"SPS\"\n\n            | summarize LastLogReceived = max(TimeGenerated)\n            | project IsConnected = LastLogReceived > ago(7d)"
            ]
        }
    ],
    "dataTypes": [
        {
            "name": "CommonSecurityLog (OneIdentity)",
            "lastDataReceivedQuery": "\nCommonSecurityLog\n| where DeviceVendor == \"OneIdentity\" and DeviceProduct == \"SPS\"\n\n            | summarize Time = max(TimeGenerated)\n            | where isnotempty(Time)"
        }
    ],
    "availability": {
        "status": 1,
        "isPreview": false
    },
    "permissions": {
        "resourceProvider": [
            {
                "provider": "Microsoft.OperationalInsights/workspaces",
                "permissionsDisplayText": "read and write permissions.",
                "providerDisplayName": "Workspace",
                "scope": "Workspace",
                "requiredPermissions": {
                    "read": true,
                    "write": true,
                    "delete": true
                }
            },
            {
                "provider": "Microsoft.OperationalInsights/workspaces/sharedKeys",
                "permissionsDisplayText": "read permissions to shared keys for the workspace. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).",
                "providerDisplayName": "Keys",
                "scope": "Workspace",
                "requiredPermissions": {
                    "action": true
                }
            }
        ]
    },
    "instructionSteps": [
        {
            "title": "1. Linux Syslog agent configuration",
            "description": "Install and configure the Linux agent to collect your Common Event Format (CEF) Syslog messages and forward them to Microsoft Sentinel.\n\n> Notice that the data from all regions will be stored in the selected workspace",
            "innerSteps": [
                {
                    "title": "1.1 Select or create a Linux machine",
                    "description": "Select or create a Linux machine that Microsoft Sentinel will use as the proxy between your security solution and Microsoft Sentinel this machine can be on your on-prem environment, Azure or other clouds."
                },
                {
                    "title": "1.2 Install the CEF collector on the Linux machine",
                    "description": "Install the Microsoft Monitoring Agent on your Linux machine and configure the machine to listen on the necessary port and forward messages to your Microsoft Sentinel workspace. The CEF collector collects CEF messages on port 514 TCP.\n\n> 1. Make sure that you have Python on your machine using the following command: python --version.\n\n> 2. You must have elevated permissions (sudo) on your machine.",
                    "instructions": [
                        {
                            "parameters": {
                                "fillWith": [
                                    "WorkspaceId",
                                    "PrimaryKey"
                                ],
                                "label": "Run the following command to install and apply the CEF collector:",
                                "value": "sudo wget -O cef_installer.py https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/DataConnectors/CEF/cef_installer.py&&sudo python cef_installer.py {0} {1}"
                            },
                            "type": "CopyableLabel"
                        }
                    ]
                }
            ]
        },
        {
            "title": "2. Forward One Identity SafeGuard logs to Syslog agent",
            "description": "Follow the [instructions in the Safeguard for Privileged Sessions Administration Guide](https://aka.ms/sentinel-cef-oneidentity-forwarding) in section \"Universal SIEM Forwarder\". Make sure to select the format \"CEF\".\n \nNote that by default there is no TLS security set up in the syslog on the Linux machine."
        },
        {
            "title": "3. Validate connection",
            "description": "Follow the instructions to validate your connectivity:\n\nOpen Log Analytics to check if the logs are received using the CommonSecurityLog schema.\n\n>It may take about 20 minutes until the connection streams data to your workspace.\n\nIf the logs are not received, run the following connectivity validation script:\n\n> 1. Make sure that you have Python on your machine using the following command: python --version\n\n>2. You must have elevated permissions (sudo) on your machine",
            "instructions": [
                {
                    "parameters": {
                        "fillWith": [
                            "WorkspaceId"
                        ],
                        "label": "Run the following command to validate your connectivity:",
                        "value": "sudo wget -O cef_troubleshoot.py https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/DataConnectors/CEF/cef_troubleshoot.py&&sudo python cef_troubleshoot.py  {0}"
                    },
                    "type": "CopyableLabel"
                }
            ]
        },
        {
            "title": "4. Secure your machine ",
            "description": "Make sure to configure the machine's security according to your organization's security policy\n\n\n[Learn more >](https://aka.ms/SecureCEF)"
        }
    ],
    "metadata": {
        "id": "28fbac9c-1909-49bb-b5f3-c42250422414",
        "version": "1.0.0",
        "kind": "dataConnector",
        "source": {
            "kind": "community"
        },
        "author": {
            "name": "One Identity"
        },
        "support": {
            "name": "One Identity",
            "link": "https://support.oneidentity.com/",
            "tier": "developer"
        }
    }
}