Skip to content

testing asim _ASim_RegistryEvent_MicrosoftSecurityEventV03#12384

Closed
v-amolpatil wants to merge 69 commits intomasterfrom
test-asim-file-ASimRegistryEventMicrosoftSecurityEvent
Closed

testing asim _ASim_RegistryEvent_MicrosoftSecurityEventV03#12384
v-amolpatil wants to merge 69 commits intomasterfrom
test-asim-file-ASimRegistryEventMicrosoftSecurityEvent

Conversation

@v-amolpatil
Copy link
Contributor

@v-amolpatil v-amolpatil commented Jun 20, 2025

Required items, please complete

Change(s):

  • This is a testing pr

Reason for Change(s):

  • See guidance below

Version Updated:

  • Required only for Detections/Analytic Rule templates
  • See guidance below

Testing Completed:

  • See guidance below

Checked that the validations are passing and have addressed any issues that are present:

  • See guidance below

Fixed by below:
Name to sample file with extension csv: Microsoft_Security Events_Authentication_IngestedLogs
In Sample data, Added a new column "ParentProcessId", I was getting error for DCR column having missmatch of data types as it was getting string to guid. InterfaceUuid, LogonGuid, SourceComputerId , SubcategoryGuid, TargetLogonGuid

Below is the error:
Response of DCR creation: {"error":{"code":"InvalidPayload","message":"Data collection rule is invalid","details":[{"code":"InvalidTransformOutput","message":"Types of transform output columns do not match the ones defined by the output stream: InterfaceUuid [produced:'String', output:'Guid'], LogonGuid [produced:'String', output:'Guid'], SourceComputerId [produced:'String', output:'Guid'], SubcategoryGuid [produced:'String', output:'Guid'], TargetLogonGuid [produced:'String', output:'Guid']","target":"properties.dataFlows[0]"}]}}

@v-amolpatil v-amolpatil self-assigned this Jun 20, 2025
@contentautomationbot
Copy link

ASIM parsers have been changed. ARM templates were regenerated from the updated KQL function YAML files.
To find the new ARM templates, pull your branch.

@contentautomationbot
Copy link

ASIM parsers have been changed. ARM templates were regenerated from the updated KQL function YAML files.
To find the new ARM templates, pull your branch.

@contentautomationbot
Copy link

ASIM parsers have been changed. ARM templates were regenerated from the updated KQL function YAML files.
To find the new ARM templates, pull your branch.

@contentautomationbot
Copy link

ASIM parsers have been changed. ARM templates were regenerated from the updated KQL function YAML files.
To find the new ARM templates, pull your branch.

v-amolpatil and others added 12 commits June 25, 2025 16:58
Changed the 'LastUpdated' date in both ASimRegistryEventMicrosoftSecurityEvent.yaml and vimRegistryEventMicrosoftSecurityEvent.yaml to June 23, 2024. Also made a minor formatting adjustment in the sample ingested logs CSV for registry events.
@contentautomationbot
Copy link

ASIM parsers have been changed. ARM templates were regenerated from the updated KQL function YAML files.
To find the new ARM templates, pull your branch.

@contentautomationbot
Copy link

ASIM parsers have been changed. ARM templates were regenerated from the updated KQL function YAML files.
To find the new ARM templates, pull your branch.

@v-amolpatil
Copy link
Contributor Author

done with testing so closing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant