Azure Sentinel destination plugin

Azure Sentinel is a cloud-native security information and event management (SIEM) service provided by Microsoft Azure. It provides intelligent security analytics and threat intelligence to help identify and respond to security threats across your organization. With the Azure Sentinel destination plugin, you can configure your Calyptia Core pipeline to send security-related logs and events to Azure Sentinel. This allows you to collect and analyze security data from various sources in real-time, and use the powerful tools and automation capabilities of Azure Sentinel to detect, investigate, and respond to security threats.

Configuration parameters

The Azure Sentinel destination plugin provides these configuration parameters.

General

KeyDescription
Customer / Workspace IDCustomer ID or WorkspaceID string.
Client Authentication KeyThe primary or the secondary Connected Sources client authentication key.

Advanced

KeyDescription
Event Type NameThe name of the event type. For example, FluentBit.
Time KeyOptional parameter to specify the key name where the timestamp is stored.
Enable Time GeneratedIf enabled, the HTTP request header time-generated-field will be included so Azure can override the timestamp with the key specified by time_key option.

Security and TLS

KeyDescription
TLSEnable or disable TLS/SSL support.
TLS Certificate ValidationTurn TLS/SSL certificate validation on or off. TLS must be on for this setting to be enabled.
TLS Debug LevelSet TLS debug verbosity level. Accepts these values: 0 (No debug), 1 (Error), 2 (State change), 3 (Informational), 4 (Verbose).
CA Certificate File PathAbsolute path to CA certificate file.
Certificate File PathAbsolute path to certificate file.
Private key File PathAbsolute path to private key file.
Private Key Path PasswordOptional password for tls.key_file file.
TLS SNI Hostname ExtensionHostname to be used for TLS SNI extension.

Advanced networking

KeyDescription
DNS ModeSelect the primary DNS connection type (TCP or UDP).
DNS ResolverSelect the primary DNS connection type (TCP or UDP).
Prefer IPv4Prioritize IPv4 DNS results when trying to establish a connection.
KeepaliveEnable or disable Keepalive support.
Keepalive Idle TimeoutSet maximum time allowed for an idle Keepalive connection.
Max Connect TimeoutSet maximum time allowed to establish a connection, this time includes the TLS handshake.
Max Connect Timeout Log ErrorOn connection timeout, specify if it should log an error. When disabled, the timeout is logged as a debug message.
Max Keepalive RecycleSet maximum number of times a keepalive connection can be used before it is retired.
Source AddressSpecify network address to bind for data traffic.