Overview of Analytic Rules
Analytic rules are scheduled queries that automatically monitor your KMIP logs for predefined threat patterns and anomalies. Unlike hunting queries which are run on-demand, analytic rules execute continuously and generate incidents when they detect suspicious activities. This enables real-time alerting and automated incident creation for your security team.
Three scheduled analytic rules ship with the solution to detect threats targeting your KMIP plane. Rules must be individually enabled from Configuration → Analytics → Rule templates.
|
Rule |
Severity |
Detection Logic |
|---|---|---|
|
Multiple KMIP authentication failures from same IP |
Medium |
≥ 5 authentication failures from one IP in 15 min |
|
|
Medium |
≥ 10 permission denied events for one user in 30 min |
|
Burst of |
High |
≥ 20 successful destroy operations by one user in 10 min |
Analytic rules
How to Enable the Rules
Follow these steps to activate each analytic rule in your Microsoft Sentinel workspace:
-
Navigate to Configuration → Analytics → Rule templates.
-
Search for
Utimaco ESKMto find the available rules. -
Select a rule to view its detection logic.
-
Click Create rule to enable it in your workspace.
-
Configure notifications and automation playbooks as needed.
The rules will begin running on schedule and automatically generate incidents in Threat management → Incidents when they detect suspicious patterns. Configured notifications will alert your team, and linked automation playbooks will trigger as needed.