Update Sentinel and Splunk analytics integrations - #33059
Conversation
Review✅ No issues found in commit Code ReviewThis code review is in beta and may not always be helpful — use your judgment. No code review issues found. ConventionsNo convention issues found. Style Guide ReviewNo style-guide issues found. CommandsOnly codeowners can run commands. Post a comment with the command to trigger it.
|
|
[AI] Triage of the code-review bot findings on
Applying fixes now. |
|
[AI] Triage of the flue review on
Applying now. |
aaeacf4 to
4b64248
Compare
|
[AI] Triage of the flue review on
Applying in commit |
5760952 to
846efb3
Compare
|
[AI] Triage of the flue review on
Applying these fixes now. |
|
[AI] Triage of the flue review on
Applying this fix now. |
c5be653 to
2a0e09f
Compare
|
[AI] Triage of the flue review on
Applying these fixes now. |
2a0e09f to
77b7c4c
Compare
|
[AI] Triage of the flue review on
Applying the four style fixes now. |
4208dea to
f29ada9
Compare
|
[AI] Triage of the flue review on
Applying this fix now. |
Expand the Sentinel page around the recommended CCF connector: detailed prerequisites (ADLS Gen2, RBAC roles, Event Grid resource provider, DCR/DCE, network access), refreshed Content hub and connector fields walkthrough, a Log Analytics verification query, and a troubleshooting entry for the CreateDataFlowResources ARM template error. Add a deprecation notice for the Azure Function-based solution. Extend the Splunk page with HEC Global Settings guidance for enabling SSL, dataset-to-sourcetype mapping for the Cloudflare App for Splunk, and a confirmation-events note when validating a new Logpush job. DEE-3779
Tie the Function-based connector deprecation notice to the public changelog entry and to Microsoft's Azure Monitor HTTP Data Collector API end-of-life on 2026-09-14. DEE-3779
- Reword Sentinel CCF connector identity references to point to the Cloudflare CCF connector application and its service principal (CR-e7252f2c3d02). - Drop directional 'below' references (SG-2d8ad00db9da, SG-6d5acda3ec8a). - Replace 'set to Enabled' / 'Only enable' toggle jargon with the style-guide 'turned on' / 'turn on' phrasing (SG-e13d4b76765b, SG-5a06a4ee4266). - Use 'Select' instead of 'Click' for the '+Add new' step (SG-c30ba167399b). DEE-3779
Move the exact 2026-09-14 end-of-support date out of the page body and admonition title into the linked changelog entry, per the style guide on time-sensitive dates outside the changelog (SG-e900072a2c83, SG-e053572c78cc). DEE-3779
Splunk: add a Splunk CIM field mappings section documenting the Cloudflare-to-CIM field mapping the Cloudflare App for Splunk applies per Logpush dataset — HTTP requests, CASB findings, DNS logs, Audit logs, Access requests, Zero Trust Gateway HTTP, Zero Trust Gateway Network. Sentinel: replace the parser/workbook/analytic-rules/hunting-queries field lists with the ASIM-normalized names the CCF connector actually emits (SrcIpAddr, HttpRequestMethod, HttpStatusCode, DvcAction, etc.), so KQL queries against the connector output match the documented names. DEE-3779
- Fix Splunk CIM referrer field name: http_referer -> http_referrer (CR-3138e225a15c). - Remove QuerySize mapping in the Gateway DNS table: CIM query_count refers to per-transaction query counts, not payload byte size (CR-1025419467c2). - Fix Splunk CIM session identifier for Zero Trust Gateway Network: ssid -> session_id (CR-15e6a491a88d). - Rename the DNS mapping section to 'Zero Trust Gateway DNS' since the fields listed apply to the gateway_dns dataset, not zone dns_logs (CR-a506e8058cfe). - Replace 'the tables below' with 'the following tables' in the Sentinel field-mappings intro (SG-9389419bc184). DEE-3779
Rewrite the two-item RBAC role lists as prose and replace a directional table reference with neutral wording. DEE-3779
Document that Contributor roles do not grant permission to create the storage-account role assignments required by the connector template. DEE-3779
Scope the Event Grid registration check to the requested subscription and use sentence case for the Splunk Task 2 heading. DEE-3779
Address the remaining active-voice suggestions while retaining the verified connector-specific requirements and changelog link. DEE-3779
Add CASB findings, Zero Trust Gateway HTTP, and Zero Trust Gateway Network to the Task 2 source-type list. These datasets use cloudflare:json; the Splunk app applies the CIM field mappings via props.conf aliases based on the JSON fields present in each dataset. DEE-3779
7dbc52a to
6bdab9a
Compare
|
[AI] Triage of the flue review on
Applying the fixes now. |
Align the remaining Sentinel workbook names with ASIM, document the Gateway DNS source type, remove misleading step-specific links, add required table introductions, and use active voice in the CIM overview. Also correct the Gateway Network session mapping to session_id. DEE-3779
Summary
What: Expand
analytics/analytics-integrations/sentinelandanalytics/analytics-integrations/splunkwith the setup and operations details customers have been asking for.Sentinel:
InvalidTemplate: CreateDataFlowResourcesARM error.Splunk:
cloudflare:json,cloudflare:dns,cloudflare:audit,cloudflare:access).Why: Customers deploying these integrations were missing prerequisites, connector-field detail, and the troubleshooting path for the most common ARM template failure. No screenshots are added; steps link out to the relevant Microsoft and Splunk docs.
DEE-3779
Documentation checklist