How to Surpress Microsoft Sentinel Log Ingestion – 51 Security
let Watchlist = datatable(Priority:string, Activity:string) [‘1’,’event:system’,‘1’,’event:user’,‘1’,’event:user logon’,‘1’,’event:vpn’,‘1’,’utm:anomaly’,‘1’,’utm:dlp’,‘1’,’utm:dlp dlp-docsource’,‘1’,’utm:dns’,‘1’,’utm:dns dns-query’,‘1’,’utm:dns dns-response’,‘1’,’utm:emailfilter’,‘1’,’utm:emailfilter bannedword’,‘1’,’utm:emailfilter spam’,‘1’,’utm:emailfilter webmail’,‘1’,’utm:ips’,‘1’,’utm:ips botnet’,‘1’,’utm:ips malicious-url’,‘1’,’utm:ips signature’,‘1’,’utm:ssh ssh-channel’,‘1’,’utm:ssh ssh-command’,‘1’,’utm:ssh ssh-hostkey’,‘1’,’utm:waf’,‘1’,’utm:waf waf-address-list’,‘1’,’utm:waf waf-custom-signature’,‘1’,’utm:waf waf-http-constraint’,‘1’,’utm:waf waf-http-method’,‘1’,’utm:waf waf-signature’,‘1’,’utm:waf waf-url-access’,‘2’,’event:cifs-auth-fail’,‘2’,’event:endpoint’,‘2’,’event:rest-api’,‘2’,’event:router’,‘2’,’event:sdwan’,‘2’,’event:sdwan down’,‘2’,’event:sdwan up’,‘2’,’event:webproxy’,‘2’,’event:wireless’,‘2’,’traffic:forward deny’,‘2’,’traffic:ztna’,‘2’,’utm:app-ctrl’ ,‘2’,’utm:app-ctrl port-violation’,‘2’,’utm:app-ctrl protocol-violation’,‘2’,’utm:app-ctrl signature’,‘2’,’utm:file-filter’,‘2’,’utm:virus’,‘2’,’utm:virus analytics’,‘2’,’utm:virus command-blocked’,‘2’,’utm:virus content-disarm’,‘2’,’utm:virus ems-threat-feed’,‘2’,’utm:virus exempt-hash’,‘2’,’utm:virus infected’,‘2’,’utm:virus inline-block’,‘2’,’utm:virus malware-list’,‘2’,’utm:virus outbreak-prevention’,‘2’,’utm:virus oversize’,‘2’,’utm:voip’,‘2’,’utm:webfilter’,‘2’,’utm:webfilter ftgd_blk’,‘2’,’utm:webfilter ftgd_err’,‘2’,’utm:webfilter urlfilter’,‘2’,’utm:webfilter webfilter_command_block’,‘3’,’event:connector’,‘3’,’event:fortiextender’,‘3’,’event:ha’,‘3’,’event:switch-controller’,‘3’,’event:wanopt’,‘3’,’traffic:forward’,‘3’,’traffic:forward accept’,‘3’,’traffic:forward client-rst’,‘3’,’traffic:forward close’,‘3’,’traffic:forward dns’,‘3’,’traffic:forward ip-conn’,‘3’,’traffic:forward server-rst’,‘3’,’traffic:forward timeout’,‘3’,’traffic:local’,‘3’,’traffic:local accept’,‘3’,’traffic:local client-rst’,‘3’,’traffic:local…
Read More “How to Surpress Microsoft Sentinel Log Ingestion – 51 Security” »