Skip to content

About

For use by the WASOC to develop code and public avaiable information for the DMARC project

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

WA DMARC Program

This repository provides an overview of the WASOC DMARC Pilot onboarding process, along with a technical onboarding guide to support integration with the DMARC platform.

Table of Contents

  1. Platform Architecture - Overview

  2. Onboarding Checklist

  3. Data Collection Rule and Logic App deployment guide

  4. Analytic Rules Deployment Guide

  5. Initiating an end-to-end test

  6. Feedback


Architecture Overview

Architecture Overview

Onboarding Checklist

Feedback

For questions or feedback, please contact cybersecurity@dpc.wa.gov.au


Data Collection Rule and Logic App deployment guide

The following steps will guide you on utilising Azure ARM templates to create a Data Collection Rule and Logic App to integrate DMARC platform with Microsoft Sentinel.

Pre-requisites:

  • Requires an Azure Log Analytics Workspace (to ingest the data from the DMARC platform).
  • A DMARC group that has been provisioned by WASOC.
  • Requires Contributor permission to the Microsoft Subscription to deploy the required resources.
  • Requires a minimum of 'User Access Administrator' for role assignment to the target subscription.

Step by step guide

Step 1.

To start the integration of the DMARC platform with your Sentinel SIEM, click on the 'Deploy to Azure' button shown below. This will deploy the Data Collection Rule and Custom tables required for the integration.

Deploy to Azure

Step 2.

You will be redirected to the custom deployment screen in azure portal. Select/ fill-in the required information.

Screenshot of the DCR ARM template Field description:

  1. Subscription: The subscriptions where the Data Collection Rules will be deployed to.
  2. Resource Group: The resource group where the Data Collection Rules will be deployed to.
  3. Workspace Name: The name of the Workspace you have selected above.
  4. Data Collection Rule Name: Name for the Data Collection Rule (Note: No special characters or numbers).

Step 3.

Review and ensure all details provided in the deployment are correct and proceed with creating the resources. Otherwise, select the 'previous' button to go back and make any changes.

Step 4.

Click on the Data Collection Rule resource that was just deployed and get the immutable id for the DCR, then click on the JSON view of the DCR resource. Screenshot of the Data Collection Rule overview

From the JSON view, get the logsIngestion url and the stream name from the streamDeclarations field.

Screenshot of the logsingestion

Now the full Log Ingestion URL is:
logsIngestionURL/dataCollectionRules/{immutable_id}/streams/{streamName}?api-version=2023-01-01

It would be similar to:

https://dmarc-dcronly******-australiaeast.logs.z1.ingest.monitor.azure.com/dataCollectionRules/dcr-9*******/streams/Custom-DmarcLogs_CL?api-version=2023-01-01

Step 5.

Now select the 'Deploy to Azure' below and open it in a new tab to deploy the Logic Apps for sending the DMARC data over to the Log Analytic workspace/datalake and fill in the following information.

Deploy to Azure

Screenshot of the Logic App ARM Template Deployment

Field description:

  1. Subscription: The subscriptions where the Logic apps will be deployed to.
  2. Resource Group: The resource group where the Logic apps will be deployed to.
  3. Logic App Name: The name of the Logic App. (Please update the 'AGENCYNAME' to reflect your agency's name)
  4. Api Token: Get your API token from the PowerDMARC Platform
  5. Stream Name : Stream name as found in the DCR JSON view under ‘streamDeclarations’. (Highlighted in previous step: Custom-****_CL)

Step 6.

Once the information has been filled in and the resources are successfully deployed, select the deployed logic app resource.

{: .important } You may need to manually assign the Monitoring Metrics Publisher role to the Managed Identity of the Logic App, scoped to the resource group that contains the Data Collection Rule (DCR). Ensure that the Logic App has its system assigned identity enabled.

Screenshot of the Enable system identity


This completes the integration for the DMARC pilot project. You can now perform testing to ensure the integration is working correctly.

About

For use by the WASOC to develop code and public avaiable information for the DMARC project

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors