From 1f223e6a005fc6451c689b02cddab0015964a3ef Mon Sep 17 00:00:00 2001 From: v-sudkharat Date: Wed, 14 Jun 2023 15:40:01 +0530 Subject: [PATCH] Repackaging- ZoomReports --- .../Data/Solution_ZoomReports.json | 6 +-- Solutions/ZoomReports/Package/2.0.2.zip | Bin 0 -> 8432 bytes .../Package/createUiDefinition.json | 2 +- .../ZoomReports/Package/mainTemplate.json | 38 +++++++++--------- 4 files changed, 23 insertions(+), 23 deletions(-) create mode 100644 Solutions/ZoomReports/Package/2.0.2.zip diff --git a/Solutions/ZoomReports/Data/Solution_ZoomReports.json b/Solutions/ZoomReports/Data/Solution_ZoomReports.json index 5ed3894fc7b..4993d36932e 100644 --- a/Solutions/ZoomReports/Data/Solution_ZoomReports.json +++ b/Solutions/ZoomReports/Data/Solution_ZoomReports.json @@ -1,8 +1,8 @@ { - "Name": "Zoom Reports", + "Name": "ZoomReports", "Author": "Microsoft - support@microsoft.com", "Logo": "", - "Description": "The [Zoom](https://zoom.us/) Reports solution enables you to ingest Zoom Reports' events into Microsoft Sentinel through the [Zoom Report REST API](https://marketplace.zoom.us/docs/api-reference/zoom-api/methods/#operation/reportSignInSignOutActivities)\r\n \r\n **Underlying Microsoft Technologies used:**\r\n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n\n a.\t [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api)\r\n\n b.\t [Azure Functions](https://azure.microsoft.com/services/functions/#overview)", + "Description": "The [Zoom](https://zoom.us/) Reports solution enables you to ingest Zoom Reports events into Microsoft Sentinel through the [Zoom Report REST API](https://marketplace.zoom.us/docs/api-reference/zoom-api/methods/#operation/reportSignInSignOutActivities).\r\n \r\n **Underlying Microsoft Technologies used:**\r\n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n\n a.\t [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api)\r\n\n b.\t [Azure Functions](https://azure.microsoft.com/services/functions/#overview)", "Data Connectors": [ "Data Connectors/ZoomReports_API_FunctionApp.json" ], @@ -10,7 +10,7 @@ "Parsers/Zoom.txt" ], "BasePath": "C:\\GitHub\\Azure-Sentinel\\solutions\\ZoomReports", - "Version": "2.0.1", + "Version": "2.0.2", "Metadata": "SolutionMetadata.json", "TemplateSpec": true, "Is1PConnector": false diff --git a/Solutions/ZoomReports/Package/2.0.2.zip b/Solutions/ZoomReports/Package/2.0.2.zip new file mode 100644 index 0000000000000000000000000000000000000000..8866ce52892b3782d69a782f66f2cd23f2688f6a GIT binary patch literal 8432 zcmZ{qQ*b6=v#n#>wrxx_v6C;h`Ng(v+nH#Bi7~Nl+qSJe|2b8sPSxJ~?TfBn)oYwhPG&|fW@P_O5+Q8Bzz-V+y<5ek^P!K2%y#EFiQ`fF0PHr2X|%Yz{jiQE_xU8l~TSdHx~IC7U-Nx-rn6-(30NX7oQ$T zP?|&6D;O(}BB!aweQRJB^4)HU%q-qq^{IrFX2RI@`fV6QwFEKy8H}lHWtrLVf;%5x6kaQ)wMwH4>)*y#1+beHJ))RVjLR5 zRKwL=CMi}c&~qF@dsCyxIGv5YPbliDIJ`Gwm&B>jvN=1~1ih}mcn$l}^G(FK-0%*q z2dp7Yiji@)1J0~>>EM{b?(QM7s9;vr==cJ&ID`sc5<}-*XyrfD9^Ts=hU?H}#dsxH zb21{0t3Ec@y^GLT?&6Hw+e_ut$kVGl{IBosqHo@EE%cfdqi$sB4@* zdjb~PGM#s=RzQ3<1{(f6(0TTx{uEA&Q9Kd_)<8_{5aVTRGt{Qqy>Vviu~}@-#Q73( zSlVE6O}+css-@q z{h_n6i7Bx!ZH&EZwqLHf?%rDyslV$sn%`E0nG{ngQ&ufYCi{+Ze&sJOk;fGc>S3+u z3jX?2WL)vMXVSOQD1Jd{q3O$I3BOe(M6^bl{NsqPKeRIx9gLgXk|_#;KJ93dJ`s?( zEE8q}$pFbfGi(mUNB9Ufz_uii?v6B!Z7ni;dsXOMZb)0zQ>`=IBdJ@1{)YB$-E}Bb zhV-zfZb(UwS2u-WEB=_jNZhpdm||NnOVk2q!Lx~f?cw%O-72$A@18E2&dO1X6ff_V z17F2r(Rh(JryU2mNp>UPMn&NW$lGO~ZhW?Pv?cNG ztUWe09@=Q_az)rQV*xP`LtXd$boXob%kuku_DdL|Mg>M#Ao0E3J$F?1I0uemNv7v!>EoKh2O^+=nZQ(EQDMK#pz!yzk@Aoa8i9P!RzhNi5T|LUG)oS|R`O;$vVf{@ zL!e4uGfRTabA;Q#5@R`|D(GeD712oUy&@O#S%o9JnR^k?1j9X~G>Mu8Ys&jxNt)($ zdZ~Eb=A>PK@8^=sdGpa^(IczGX}$vnLv!3oM^2VbQOH7KEZz-bQ<(*#t3%aWVj3Q=X=ic zAyc&*^q0)*h)|N%WOfvB8~mnWjS!w)$LiEAmgg*CqV*h$mD2H!7gdbwXE!fxo#y+u zp*E6Z5UFCd;)|n3w!t4p`xrGLymLO6A>)}=tiw(TiI3dsbqVk6wR&P{98~ z>Fz(2=Aj*UZ{UD{pjU!`p#DRttr5^p)y&qx<{wc14@55oterQwlD1o{zQNU7>42pi zePSh)Dmqap_A(DB5C zU+X8c`I7NS$RcSHql8cGhS40qc=5j}l3prveR+iw26%P7$Ju(5agKQjg!+Wu-hvJ} zig}H1;JJRHGv0Y787*V;kDw*$9-4}YC6-F3eGm6Fl8V4ZfPA2Z|~ zI{)?3I zTQ`D>h)Oql9P{CkZMsZW0*a5z;ZM=xOf&(DO<{`L9Y|YKZ%W!OBt&)?Kp6Z?{dkzX zTEsPSc(P7$Fm})eK@|e~>}JrAc@P~!Q%%`d8?}lrEYV|y&Z7$qNB)M+EOWyLFLx+t`lywM zMw;2}IdYPQ(sGp6yf28D`W7=kH!Pe7wW1vEct{-I`8+9Bs2)l;B2XpyLX*~j`Xnyy zi6hT$ixv^)3DoP?Sk1{_i}@RIYDD|=!d=0-f}Dne5f49&px;KJhE?LPSO)7EkxZz34Du$!D&1pXo< z^FMX@$hp#l`Aaa=y-TLm9OuT>PlCAnrHns;%tpUt{$aXnvd{^rnFhK}kpYOo%@LnU}IyqEjc z9W`)Q^ES4=ekgyRqHuL1UfoPtv9-kTnUn4SV8Y|A;0iC+)cFOD2ym{$L_O9YhzV<# z7r`h4tchevzw-uB6rt@E2z`Bm0B$t6U$Jq}8=nQ#_P~@#zA(#}aZjSuwtO7mIz0pr z;sK0jzK_NL8w(aVa!g}}gznD~;EuMB)Bl6ln0h zME}lYkt1rbtU22F0C3h9=mA!4Cm{3hAcA^)EYiin6*)92!>oWyq@Mt%mt#2NV;)1a zNYv*3rRihWBxE+!bCU0=_F&WbeJwbH$UOHDTUzxCx}J2b?U-hV4=Hez+^CMvzIm!lJW8SZOvjogUxm{w6}ZvJ8^cqGaCSE zyKRCW`FxP?fbAlmciK>nz zMe_)^Fm)$yLO=f``-ACteHABM4jMkwG-9?9t5PTcEeb8PY3Fja%$|NRFWYzg^W%7Q zV#bfwDyZudmW2YVnxz`{6ko(*bjv`LI5V&`dp>^)Km_DFa5ex0^ul5NWez8Dx^i$# ztHYnNE1buSg>Zg+Kac>6ISqox^m%h+$-B#ZLT`7Q8mAtsVc$=8Q~1jaL&wx=qAAcy^Udr+9c| zP^5;RUK85p*GYrwaDsSM$m#Xzfsbb|{8tz6;m-*p>VE&)_SlReb4&+u41g0Npd@;= z_s79qPC0%gCp1=}Sd4j{lVUF|gA+W2NVAWwgXM6OH!n2Xocebhmh?n#qCiguUgril z%<#UC3%szJ6MdIVDKErR5gpe4E=-6ag!2mlg(wEM#WUJ{e$N8O%+zoj!AaMS`nV;| zETo=GMxWgh=a%STvrz46AV@C;m%VFJ`L0Xn6FvLR9|?{qc~A#7mtr$|UKy2+(N?S) zE-K9|Em`I-kc?};$6(U>NRm-j1{p};o}oNlW$hu&Vb23f2TA96sWTMCWZfd#%Uwul zl#xc^$tuua6CRag{O6)@Rc=&pzTJIrjrmwzAixizd(coW?wBDU0`cQ!yb2CMt;4k> zh#?Z4$aN%Y394GCNw;H;I|B`t?#=z8NfJ$Ok|=yodzcq0{+y>O*7w_-$LIBIZxwxI z6COdh(gk#&wU1W60@_b}4G$|JTnTOk4hbKHlHDH7w2Df*0J2{cM?A%(N_X&uu1^&g z|DccrwUs41Rz;tyPKH!!&{wLLM3c2aZf=QE^*N+7yb~N)SFCzfZufloOHp5g^m(gN zwFdp!0VE{7Tp4Q<70{_Q*#kyQ4qUvY`BECiSZNS26y_Kn<&3`Nn^ByFC{FJf1gF|J z4^I73$|R7$V#t`!hz{j=bh67~?JpoU1*axs(*!*;P%lT>#iXf`keg35Tt!5-+MZ>L zw?k=F$}|ifJRy)p_s`rca}1_bY7siHTMQ{mv|r#>+|Z(|XyB#%H3gxPTg67+=rT84 z?@EI?<+9+H8Sh1dhZug0Jv}u-ikrBv?WS1L60>Z%FyQdQ6!v#P`x)HQq99m#iVocd zXmQ8nXDGriAu@qJ;nwB#TJ?ju>;l!Q{9}ngLT4n$RJ%gmSB$Zy#8!!-E)*^iLiZ^0 zjI2NkuEXnX?_%*hx+oocq;|W$QtVI=v^Zz!B8bnsOY!JI!cqBjGHD*2*LTq&?G|$K zs#x<1k|b6|jPvkmw8yDLPrt=>{72`cf=0w&MQ1NQgIk)nz;TmoLiDq#r`Xl2DM9-+ zA2+feW=f0zkU2N7NAIu~+IfXxX|M1Wx4d!K57D-sPwj`r4u~oj`-7&H`+OO_ZAybu z8x_6#p^adGdtq@JBsHnl35QdOZZ*TDPC)o#qtRI&QP$!zGt5@a(E8$UMWo*SsJ~Bt z!}`(xWVsAL!kKFycm~0Ngb+T`eT*`HyOi_kpTsd*mnMv(pW@Qs1p6gZdsh|)yWj4! zzQ`rIh=8`L{y@e_3V>rOr7R2+ZS*@D0ZX)~9iJH@NFqW)eYTe}J5BU&Iz;JtJ>)fF z69swqXpas!TA%C<{RHVWyAu}io!Z|67j73j1G#~5ie!85fn2MAGCbWj^iUO9a4?)U z%x^4=U$r$MuvuC*xkLE#Ym1IAVVydThKY+INcQ_aW5-v+%w=XUkBT?~gGL(QAZURb z<~Ft-uJ!Qw!;ti_7CuNz`vhTj6H(>iBibl$_XYuw8>|9>o{m*L&Xn?;mzvE$2yb>h zmg_@`Y;0?a@w4u6My%c^SZ>SpRbBhYvyl2&!a+X(`118burp5 zzQU*u6C5r}01WkxMQGK0GZ!#Ia1@@Gv<@WL&T`@%KtX^coNYM>P#m}19z^T@2EA>A zWGAyGIFNTtxW-^dwx5PwVrD?M=U`(wY)M2bn#G(J(|5xuaVPP*)nG}KBOh@|je^Du zl#~3GtLzCSML(K+z!isv*G8tIYt(JWJ|nziq)fz$a*XULA*`{3tKvsqqPS%?JWrVz z3kfhy#3D&GDZzBkI+UU@O{}{W?FP?~Am3f3uEldC4b@!aPS8LZ-s!vo^u4x~>fKXN zqAEmyfe@zT4`T$KJb^l}rg@1eh8JNF^4zp%YHrhZ2E)Mm$Xn9ZAcWUHCr2TxRYYC| zi_np-QT^UPjv^>#MBQ=lqHJQ15r32;mjjBbPFk>%jP2ufybq!bu`;P1Frvd z;dxR(+fesL?#IW2#<7<@0f*!g>qrqUHpQY;DYsbcJ+9!AP+rzfLAdL^4rZ;7F9!9{ z6R>hMD{@)Oj6wl-xp<$k~#&znQ*qr-l{OV7jo$x9TcL~~<~1l~6%z?BzU z()(infxr=(A#N;F55_SZr1c<>92M;&@Rd#Epq7-Pt|s?acij=iqZaZh=TM3qrjF8L z@W(F12h<<7Q}cQ4Hn#M!^wX)ja={Fx^9r7%l{&!QXN}1^lk}w!B*_jtVIt4yE9NqN zFF{P3WboGz=CAENg^S_^AI+huG)V*kf5a{Dr=Tg+bea!Wxh}>1<2ZCBc#C*iY;!GLqB*b!j)LxP|grEZ)8 zJzZCh!ZSU}0i^?$?Q_aZPYOXOsS!s;HlTRUGEVs9CafSt^c4T{9KF+dh~0EcHE*Sd z16Q5-WPzfTG^C0Hya7=IT9E~7bo($BU-$jbhT)>B_zQJxn3HPC#28!~H!ihzGg4~`B$}8sD&6kDzB_Q>$qd;u zjSZ0gd>a;}upkA8;>mV&oz{Nm>vVsl`xusK=aDur@>UD{DeUKJ5xWRgy@p|CnwLNv z8}j{L*FhdpLbDx{42VfiIbWZC!*LM_2U-hwwWvd}tU+S^BHIQR z7<2Xy%;YDHX+jGQdKxvphTB6tI45{}D4s5kwtLp+{r`Vj22`fhx1TI~`^ zT!DIXgA{nrUaI-Zsn~O6D`}QfQ_jxD8Vzu_k`=V0e64?N&1DyGbi18TB4W7dDKlnRSN@JO z{?Yvg_ZD@`MeBD?@3oHAZX3PnGiWE!que7K3L)HgNXHvP299Rqhs@s zP0Mzs?NqDFnkckAW5Buv2|=r+i5pqZyJ4!@r<{|EetyrnrbNrVcRed}Dl3!H z%4`E^kF5z`cF~4G34Z>8YSJQfExmb|0+c}~b{Fq!#^v;n(J8g8!Q@z}Dv*m4oxO7G zqWQ^G$NSD~F>ga>ax|;{fp;NoLqmRajACsm&c<4jt9-&T3+4UyOS7A)4qyEr!qug? z6#Q4~rMN01+!juhHdPzG#yiMt8k z^1MvV_^$l=gP;33BcDxq7O>muGP4oR9Rn&DwE$ES8o2A&Yv%zYXNvbWuBD+mlg~ou z=ab4qd)?j&__$+IDdTX%Z5ZtlG@|U}{qg z1LtRn+@}Hy_kH90(%DN7;7$g944A`wl?NJ{P&rU_-lqhR`lONWsNLS~Z>sP!ACm5O zA%DV&Ydv6OZR3D+^plTW029Op$?|UKGtD&)1!_S6neB!?XW$2pi|Af0b0jcDBxxf9 zj$pGs-V_6;$zU~#BF8t_G1A=Y>^_Ce-V(udVJjhJ98RQhN}O)7zP%wJ&UHgK^R)sI;dxW`2j|4IW5-BLw@BV$W^zay zwXG(loZ+pf5ppZy&;+Mj02qBjp_uWoYXxjpA2TaO#($m()=3kF!URtN}1cKmS zmN;5BzLz%1tL(S23Qn47mXl|F2`0Fbl zd#W$zTOa04RO1@<>saX+m*4rB6oXniwo=cm-Tb$qwzCCgFRA;h?lCgF;2f6UTh(d zKQ0#7s&AKWaaCT6Id(pLWc4>|eg0DvK%S@$bYLT018f@J)~mYQZ+)^CTioqRQa-pU zyC=`=|D*bKO`g#&_^W97@@4yfM`pfz8NaQ0rf;j)`?Q8v>aeKu4S!_I2G-=iT}gS? zq@HaF4t+e|;@nRwih7o;8sEE>3uABNmGh-jLfD@h5;4-|yFN7yFEma#i8l8gV|GEK zR|}Tw>%CkYW;pftIEuOr7ek_a%#J4y4Fvj0JWipxl6BTJ&wPIP5HLL=AtDZ$Xj!q? zfU7{y_=go-3tqiFDaRYEad5G;_^-8`T`;CA67j0k;Pm{iSB~_@75HkaCW}$Fy>h&t z2=gu4-dJ#QRLwB7P2JZVjZ*{F*Gah#GbwSs9%ZHwEKy0)RH#mCO~&xlKB(|Gi}w%c z{zeAKf`Vay{O`Gfe|`uEC\n\n**Note:** _There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing._\n\nThe [Zoom](https://zoom.us/) Reports solution enables you to ingest Zoom Reports' events into Microsoft Sentinel through the [Zoom Report REST API](https://marketplace.zoom.us/docs/api-reference/zoom-api/methods/#operation/reportSignInSignOutActivities)\r\n \r\n **Underlying Microsoft Technologies used:**\r\n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n\n a.\t [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api)\r\n\n b.\t [Azure Functions](https://azure.microsoft.com/services/functions/#overview)\n\n**Data Connectors:** 1, **Parsers:** 1\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", + "description": "\n\n**Note:** _There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing._\n\nThe [Zoom](https://zoom.us/) Reports solution enables you to ingest Zoom Reports events into Microsoft Sentinel through the [Zoom Report REST API](https://marketplace.zoom.us/docs/api-reference/zoom-api/methods/#operation/reportSignInSignOutActivities).\r\n \r\n **Underlying Microsoft Technologies used:**\r\n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n\n a.\t [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api)\r\n\n b.\t [Azure Functions](https://azure.microsoft.com/services/functions/#overview)\n\n**Data Connectors:** 1, **Parsers:** 1\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", "subscription": { "resourceProviders": [ "Microsoft.OperationsManagement/solutions", diff --git a/Solutions/ZoomReports/Package/mainTemplate.json b/Solutions/ZoomReports/Package/mainTemplate.json index 7ddada13ce9..80970a867ba 100644 --- a/Solutions/ZoomReports/Package/mainTemplate.json +++ b/Solutions/ZoomReports/Package/mainTemplate.json @@ -55,7 +55,7 @@ "resources": [ { "type": "Microsoft.Resources/templateSpecs", - "apiVersion": "2021-05-01", + "apiVersion": "2022-02-01", "name": "[variables('dataConnectorTemplateSpecName1')]", "location": "[parameters('workspace-location')]", "tags": { @@ -69,7 +69,7 @@ }, { "type": "Microsoft.Resources/templateSpecs/versions", - "apiVersion": "2021-05-01", + "apiVersion": "2022-02-01", "name": "[concat(variables('dataConnectorTemplateSpecName1'),'/',variables('dataConnectorVersion1'))]", "location": "[parameters('workspace-location')]", "tags": { @@ -80,7 +80,7 @@ "[resourceId('Microsoft.Resources/templateSpecs', variables('dataConnectorTemplateSpecName1'))]" ], "properties": { - "description": "ZoomReports data connector with template version 2.0.1", + "description": "ZoomReports data connector with template version 2.0.2", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('dataConnectorVersion1')]", @@ -89,16 +89,16 @@ "resources": [ { "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/',variables('_dataConnectorContentId1'))]", - "apiVersion": "2021-03-01-preview", + "apiVersion": "2022-10-01", "type": "Microsoft.OperationalInsights/workspaces/providers/dataConnectors", "location": "[parameters('workspace-location')]", "kind": "GenericUI", "properties": { "connectorUiConfig": { "id": "[variables('_uiConfigId1')]", - "title": "Zoom Reports (using Azure Function)", + "title": "Zoom Reports (using Azure Functions)", "publisher": "Zoom", - "descriptionMarkdown": "The [Zoom](https://zoom.us/) Reports data connector provides the capability to ingest [Zoom Reports](https://marketplace.zoom.us/docs/api-reference/zoom-api/reports/) events into Microsoft Sentinel through the REST API. Refer to [API documentation](https://marketplace.zoom.us/docs/api-reference/introduction) for more information. The connector provides ability to get events which helps to examine potential security risks, analyze your team's use of collaboration, diagnose configuration problems and more.", + "descriptionMarkdown": "The [Zoom](https://zoom.us/) Reports data connector provides the capability to ingest [Zoom Reports](https://developers.zoom.us/docs/api/rest/reference/zoom-api/methods/#tag/Reports) events into Microsoft Sentinel through the REST API. Refer to [API documentation](https://developers.zoom.us/docs/api/) for more information. The connector provides ability to get events which helps to examine potential security risks, analyze your team's use of collaboration, diagnose configuration problems and more.", "additionalRequirementBanner": "These queries and workbooks are dependent on a parser based on Kusto to work as expected. Follow the steps to use this Kusto functions alias **Zoom** in queries and workbooks [Follow steps to get this Kusto functions>](https://aka.ms/sentinel-ZoomAPI-parser).", "graphQueries": [ { @@ -161,7 +161,7 @@ }, { "name": "REST API Credentials/permissions", - "description": "**ZoomApiKey** and **ZoomApiSecret** are required for Zoom API. [See the documentation to learn more about API](https://marketplace.zoom.us/docs/guides/auth/jwt). Check all [requirements and follow the instructions](https://marketplace.zoom.us/docs/guides/auth/jwt) for obtaining credentials." + "description": "**ZoomApiKey** and **ZoomApiSecret** are required for Zoom API. [See the documentation to learn more about API](https://developers.zoom.us/docs/internal-apps/jwt/#generating-jwts). Check all [requirements and follow the instructions](https://developers.zoom.us/docs/internal-apps/jwt/#generating-jwts) for obtaining credentials." } ] }, @@ -176,7 +176,7 @@ "description": ">**NOTE:** This data connector depends on a parser based on a Kusto Function to work as expected. [Follow these steps](https://aka.ms/sentinel-ZoomAPI-parser) to create the Kusto functions alias, **Zoom**" }, { - "description": "**STEP 1 - Configuration steps for the Zoom API**\n\n [Follow the instructions](https://marketplace.zoom.us/docs/guides/auth/jwt) to obtain the credentials. \n" + "description": "**STEP 1 - Configuration steps for the Zoom API**\n\n [Follow the instructions](https://developers.zoom.us/docs/internal-apps/jwt/#generating-jwts) to obtain the credentials. \n" }, { "description": "**STEP 2 - Choose ONE from the following two deployment options to deploy the connector and the associated Azure Function**\n\n>**IMPORTANT:** Before deploying the Zoom Reports data connector, have the Workspace ID and Workspace Primary Key (can be copied from the following).", @@ -230,7 +230,7 @@ "version": "[variables('dataConnectorVersion1')]", "source": { "kind": "Solution", - "name": "ZoomRe ports", + "name": "ZoomReports", "sourceId": "[variables('_solutionId')]" }, "author": { @@ -287,9 +287,9 @@ "kind": "GenericUI", "properties": { "connectorUiConfig": { - "title": "Zoom Reports (using Azure Function)", + "title": "Zoom Reports (using Azure Functions)", "publisher": "Zoom", - "descriptionMarkdown": "The [Zoom](https://zoom.us/) Reports data connector provides the capability to ingest [Zoom Reports](https://marketplace.zoom.us/docs/api-reference/zoom-api/reports/) events into Microsoft Sentinel through the REST API. Refer to [API documentation](https://marketplace.zoom.us/docs/api-reference/introduction) for more information. The connector provides ability to get events which helps to examine potential security risks, analyze your team's use of collaboration, diagnose configuration problems and more.", + "descriptionMarkdown": "The [Zoom](https://zoom.us/) Reports data connector provides the capability to ingest [Zoom Reports](https://developers.zoom.us/docs/api/rest/reference/zoom-api/methods/#tag/Reports) events into Microsoft Sentinel through the REST API. Refer to [API documentation](https://developers.zoom.us/docs/api/) for more information. The connector provides ability to get events which helps to examine potential security risks, analyze your team's use of collaboration, diagnose configuration problems and more.", "graphQueries": [ { "metricName": "Total data received", @@ -307,7 +307,7 @@ { "type": "IsConnectedQuery", "value": [ - "Zoom_CL\n | summarize LastLogReceived = max(TimeGenerated)\n | project IsConnected = LastLogReceived > ago(30d)" + "Zoom_CL\n | summarize LastLogReceived = max(TimeGenerated)\n | project IsConnected = LastLogReceived > ago(7d)" ] } ], @@ -351,7 +351,7 @@ }, { "name": "REST API Credentials/permissions", - "description": "**ZoomApiKey** and **ZoomApiSecret** are required for Zoom API. [See the documentation to learn more about API](https://marketplace.zoom.us/docs/guides/auth/jwt). Check all [requirements and follow the instructions](https://marketplace.zoom.us/docs/guides/auth/jwt) for obtaining credentials." + "description": "**ZoomApiKey** and **ZoomApiSecret** are required for Zoom API. [See the documentation to learn more about API](https://developers.zoom.us/docs/internal-apps/jwt/#generating-jwts). Check all [requirements and follow the instructions](https://developers.zoom.us/docs/internal-apps/jwt/#generating-jwts) for obtaining credentials." } ] }, @@ -366,7 +366,7 @@ "description": ">**NOTE:** This data connector depends on a parser based on a Kusto Function to work as expected. [Follow these steps](https://aka.ms/sentinel-ZoomAPI-parser) to create the Kusto functions alias, **Zoom**" }, { - "description": "**STEP 1 - Configuration steps for the Zoom API**\n\n [Follow the instructions](https://marketplace.zoom.us/docs/guides/auth/jwt) to obtain the credentials. \n" + "description": "**STEP 1 - Configuration steps for the Zoom API**\n\n [Follow the instructions](https://developers.zoom.us/docs/internal-apps/jwt/#generating-jwts) to obtain the credentials. \n" }, { "description": "**STEP 2 - Choose ONE from the following two deployment options to deploy the connector and the associated Azure Function**\n\n>**IMPORTANT:** Before deploying the Zoom Reports data connector, have the Workspace ID and Workspace Primary Key (can be copied from the following).", @@ -413,7 +413,7 @@ }, { "type": "Microsoft.Resources/templateSpecs", - "apiVersion": "2021-05-01", + "apiVersion": "2022-02-01", "name": "[variables('parserTemplateSpecName1')]", "location": "[parameters('workspace-location')]", "tags": { @@ -427,7 +427,7 @@ }, { "type": "Microsoft.Resources/templateSpecs/versions", - "apiVersion": "2021-05-01", + "apiVersion": "2022-02-01", "name": "[concat(variables('parserTemplateSpecName1'),'/',variables('parserVersion1'))]", "location": "[parameters('workspace-location')]", "tags": { @@ -438,7 +438,7 @@ "[resourceId('Microsoft.Resources/templateSpecs', variables('parserTemplateSpecName1'))]" ], "properties": { - "description": "Zoom Data Parser with template version 2.0.1", + "description": "Zoom Data Parser with template version 2.0.2", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('parserVersion1')]", @@ -500,7 +500,7 @@ }, { "type": "Microsoft.OperationalInsights/workspaces/savedSearches", - "apiVersion": "2021-06-01", + "apiVersion": "2022-10-01", "name": "[variables('_parserName1')]", "location": "[parameters('workspace-location')]", "properties": { @@ -547,7 +547,7 @@ "apiVersion": "2022-01-01-preview", "location": "[parameters('workspace-location')]", "properties": { - "version": "2.0.1", + "version": "2.0.2", "kind": "Solution", "contentSchemaVersion": "2.0.0", "contentId": "[variables('_solutionId')]",