-
Notifications
You must be signed in to change notification settings - Fork 3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
New solution components #9322
New solution components #9322
Conversation
…z/Azure-Sentinel into New-Solution-Components
Hello @nlepagnez, Thanks for raising this PR. This PR will be investigated and will update you about the same before 06 November, 2023. |
@v-prasadboke in addition to analyze this PR, please can you change the pointer of aka.ms/sentinel-ESI-ExchangeConfiguration-OnPrem-parser and aka.ms/https://aka.ms/sentinel-ESI-ExchangeEnvironmentList-OnPrem-parser links as your team is the owner of those links and you didn't update the files when you switch from TXT to YAML files. (Or you can add me as owner too to those links if you prefer). |
…z/Azure-Sentinel into New-Solution-Components
Hello @nlepagnez, I'll take a look at the links and update the same. |
Hello @nlepagnez I'm getting this error for ExchangeAdminAuditLogs Is this expected or can you share screenshots of the results. |
Hi @v-prasadboke , I was unable to reproduce the problem you have. This parser is dependant of the ExchangeConfiguration parser. Can you confirm that the ExchangeConfiguration parser works well has usual (No change made in this parser and as usual, you need one of the ESIExchange* custom table). Also, as usual, Sample data for the ExchangeAdminAudiLogs is present in Sample Data\Custom\ESI-ExchangeAdminAuditLogs-SampleData.json since multiple months to fill the Event table that the parser use. |
Hi Nicolas, Thanks for sharing the Working screenshot. I guess I checked esiadmin sample data but I didnt find the columns. Maybe I must have missed it, I'll take a look again and come back to you by 10 November, 2023. |
Hi Prasad, perhaps I misunderstand the sample data you wait. Is it the input sample data of the parser or the output sample data ? You can find the output structure here : .script\tests\KqlvalidationsTests\CustomFunctions\ExchangeAdminAuditLogs.json |
I'll take a look at Nicolas, Thanks. |
Hello @nlepagnez, sorry for the inconvenience but due to lack of availability we were unable to investigate this PR. |
hi @v-atulyadav, @v-prasadboke, can you confirm me that the new packages are published ? |
Required items, please complete
Change(s):
Version Updated:
Testing Completed:
Checked that the validations are passing and have addressed any issues that are present: