Opensource NoSQL databases are being utilized more than ever in application development and at enterprises. In this video I will explore Cassandra Database and show you how to bring the Audit logs into Azure Sentinel using custom logging. We will finish by creating a Function Parser to easily call in KQL searches. #AzureSentinel #CassandraDB #Azure #LogAnalytics
********************************* Links 🔗 *********************************
Walkthrough in blog:
Cassandra Database Audit logs:
https://github.com/Azure/Azure-Sentin...
https://cassandra.apache.org/doc/4.0/...
Thousands of unauthenticated databases exposed: https://redhuntlabs.com/blog/thousand...
Azure Monitor Agent (AMA): https://docs.microsoft.com/en-us/azur...
Collect Custom Logs: https://docs.microsoft.com/en-us/azur...
Azure Sentinel Cassandra Database Audit Log Parser: https://github.com/Azure/Azure-Sentin...
Azure Sentinel Parsing Text: https://docs.microsoft.com/en-us/azur...
********************************* Chapters 📚 *****************************
00:45 compare and contrast Log Analytics Agent & Azure Monitor Agent
03:01 install Cassandra database
09:07 dive into Cassandra audit logging documentation
16:10 configure the cassandra.yaml and logback.xml for audit.log
22:20 generate audit events with cqlsh
26:50 azcopy to upload a audit.log copy for custom log
31:05 create custom log in Azure Sentinel
40:52 work with CassandraAuditLog_CL and create a KQL Function Parser
*************************** Credits 🧾 *************************
Thank you to Jing Nghik and Josh Heizman for your insights that helped me make this video.