https://catalogartifact.azureedge.net/publicartifacts/azuresentinel.azure-sentinel-solution-alibabacloud-networking-a85f528e-92ed-4770-a5cc-c1f6db2c295c/877d1730-aebd-4651-bc0d-1c2ed9f52cd5_216.png

Alibaba Cloud Networking

door Microsoft Sentinel, Microsoft Corporation

Alibaba Cloud Networking

Alibaba Cloud Networking Solution for Microsoft Sentinel

Integrates Alibaba Cloud network data (API Gateway, VPC Flow, WAF) into Microsoft Sentinel for threat detection and investigation in multi-cloud environments.


Overview

This solution provides a Codeless Connector Framework (CCF) based data connector that ingests Alibaba Cloud networking logs into Microsoft Sentinel. It enables security teams to gain visibility into network activity across Alibaba Cloud environments alongside other cloud and on-premises data sources.


Data Sources

Alibaba Cloud network data (API Gateway, VPC Flow, WAF) using the https://www.alibabacloud.com/en/product/log-service

Components

  • CCP Data Connector — Polling-based connector with DCR for log ingestion
  • KQL Parsers — Three alias function parsers normalizing raw logs for each data source: