Azure Front Door

Version: Azure Front Door.

Azure Front Door is Microsoft’s modern cloud Content Delivery Network (CDN) that delivers fast, reliable, and secure global access to static and dynamic web content for users and applications.

Netsurion Open XDR manages logs retrieved from Azure Front Door through Azure Event hub. The alerts, reports, dashboards, and saved searches in Netsurion Open XDR are enhanced by capturing important and critical activities in Azure Front Door.

The following are the key assets available in this Data Source Integration.

Alerts

TypeNameDescription
SecurityAzure Front Door – Access control violation detectedGenerated when an unauthorized/unauthenticated action is detected by Azure Front Door.
SecurityAzure Front Door – Potential threat detectedGenerated when a potential threat event is detected by Azure Front Door.

Reports

TypeNameDescription
SecurityAzure Front Door – WAF eventsProvides details about the events that match a Web Application Firewall (WAF) rule in Azure Front Door.
ComplianceAzure Front Door – Audit eventsProvides details about all the requests that go through the Azure Front Door.

Dashboards

TypeNameDescription
OperationalAzure Front Door – Geolocation of source IP addressDisplays geolocation based on source IP address of Azure Front Door access log.
OperationalAzure Front Door – Request overviewDisplays Azure Front Door request based on HTTP requests.

Saved Searches

TypeNameDescription
SecurityAzure Front Door – WAF eventsProvides details about the events that match a Web Application Firewall (WAF) rule in Azure Front Door.
ComplianceAzure Front Door – Audit eventsProvides details about all the requests that go through Azure Front Door.

Documentation

The configuration details are consistent with Netsurion Open XDR 9.3 and later, and Azure Front Door.

Download the Integration Guide for configuration instructions and more information.