This article covers how to deploy the SonicWall ASIM parsers into your Microsoft Sentinel workspace. While the parsers are built into every Microsoft Sentinel workspace for broader use and unification of NetworkSession or WebSession events across multiple vendors, deploying the SonicWall parsers into the workspace enables the Workbooks, Analytic Rules, Hunting Queries, etc. to function using the workspace function names, rather than the built-in function names.
Instructions
To install/deploy each parser into your Microsoft Sentinel workspace:




You may need to refresh your browser window or exit and re-enter your Microsoft Sentinel workspace to refresh the list of workspace functions.