{
  "Name": "VMware SASE",
  "Author": "VMware by Broadcom",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/vmware_sase_logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [VMware SASE](https://sase.vmware.com/) solution provides the capability to ingest telemetry and event data from your VMware SD-WAN fabric and Cloud Web Security service into Microsoft Sentinel through Syslog and the Orchestrator REST API.\r\n  \r\n  **Underlying Microsoft Technologies used:** \r\n\r\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n\n  a. [Azure Monitor Log Ingestion API](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview)\r\n\n \r\n\n  b. [Azure Functions](https://azure.microsoft.com/services/functions/#overview)\r\n\n \r\n\n c. [Azure Monitor Agent for Syslog collection](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/agents-overview) \r\n\n",
  "Data Connectors": [
    "Data Connectors/Function App Connector/VMwareSASE_API_FunctionApp.json"
  ],
  "Workbooks": [
	"Workbooks/VMwareSASESOCDashboard.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/vmw-sase-cws-policy-publish.yaml",
    "Analytic Rules/vmw-sase-cws-policychange.yaml",
    "Analytic Rules/vmw-sase-cws-policyviolation.yaml",
    "Analytic Rules/vmw-sase-cwsdlp-violation.yaml",
    "Analytic Rules/vmw-sdwan-device-congestion.yaml",
    "Analytic Rules/vmw-sdwan-idps-alert-api.yaml",
    "Analytic Rules/vmw-sdwan-idps-alert-syslog.yaml",
    "Analytic Rules/vmw-sdwan-idps-update-success.yaml",
    "Analytic Rules/vmw-sdwan-idps-updatefailed.yaml",
    "Analytic Rules/vmw-sdwan-ipfrag-attempt.yaml",
    "Analytic Rules/vmw-sdwan-lanside-devicedetect.yaml",
    "Analytic Rules/vmw-sdwan-nsd-cssdown.yaml",
    "Analytic Rules/vmw-sdwan-orchestrator-config-change.yaml",
    "Analytic Rules/vmw-sdwan-rpfcheck.yaml"
  ],
  "Hunting Queries": [
    "Hunting Queries/VECOfrequentFailedLogins.yaml"
    ],
  "Playbooks": [],
  "Metadata": "SolutionMetadata.json",
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\VMware SASE",
  "Version": "1.0.0",
  "TemplateSpec": true,
  "Is1PConnector": false
}
