Skip to content

CiscoDuo TI rule fails to deploy due to wrong table name DuoSecurityAuthentication_CL #13701

@presidio-ddg

Description

@presidio-ddg

https://github.com/Azure/Azure-Sentinel/blob/b11e86a2a113b3103cf0d2555bb84794ca1c1006/Solutions/Threat Intelligence (NEW)/Analytic Rules/IPEntity_DuoSecurity.yaml#L45C8-L45C36

Hi.

Solutions/Threat Intelligence (NEW)/Analytic Rules/IPEntity_DuoSecurity.yaml

https://github.com/Azure/Azure-Sentinel/blob/b11e86a2a113b3103cf0d2555bb84794ca1c1006/Solutions/Threat%20Intelligence%20(NEW)/Analytic%20Rules/IPEntity_DuoSecurity.yaml#L45C1-L45C1

references table DuoSecurityAuthentication_CL which does not seem to exist.

Instead, table name with matching schema seems to be CiscoDuo_CL.

See also rules in https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/CiscoDuoSecurity/Analytic%20Rules

Regards.

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions