Conversation
|
🔒 Security Approval Required This fork PR requires manual approval before automated testing can run. For security, a maintainer must:
Note: If new commits are added later, simply remove and re-add the 🤖 Automated security check • Created: 2025-12-11T13:56:42.474Z |
|
🔒 Security Approval Required This fork PR requires manual approval before automated testing can run. For security, a maintainer must:
Note: If new commits are added later, simply remove and re-add the 🤖 Automated security check • Created: 2025-12-12T03:15:51.630Z |
|
Hi @gbarbieru, |
|
@v-atulyadav i will open a separate PR for the ASIM rules |
|
🔒 Security Approval Required This fork PR requires manual approval before automated testing can run. For security, a maintainer must:
Note: If new commits are added later, simply remove and re-add the 🤖 Automated security check • Created: 2025-12-16T12:29:05.729Z |
d349653 to
a845d85
Compare
|
🔒 Security Approval Required This fork PR requires manual approval before automated testing can run. For security, a maintainer must:
Note: If new commits are added later, simply remove and re-add the 🤖 Automated security check • Created: 2025-12-16T12:31:01.249Z |
|
🔒 Security Approval Required This fork PR requires manual approval before automated testing can run. For security, a maintainer must:
Note: If new commits are added later, simply remove and re-add the 🤖 Automated security check • Created: 2025-12-16T12:31:28.024Z |
|
#13330 PR for ASim parsers |
|
Hi @gbarbieru,
|
|
hi @v-atulyadav |
|
Qs about: https://github.com/Azure/Azure-Sentinel/actions/runs/20306048443/job/58524457107
|
|
hi @v-atulyadav
|
|
Minor fix for tactics field |
|
Hi @gbarbieru,
|
|
Fixed branding issue |
|
Can you please trigger another test run? |
|
@v-atulyadav Seems like we still get the following error even though we added a GUID like id to the log |
|
Hi @gbarbieru, @rvirjoghe-bd, please remove the id properties from the tag below.
|
|
Hi @gbarbieru, |
|
hi @v-atulyadav, regarding the custom function part: i've asked a question that i didn't get an answer to: if you missed the question and i truly have to create that file, i will |
No need to merge ASIM PR before this PR. |
|
@v-atulyadav added the CustomFunctions file |
|
@v-atulyadav you should have received an invite to our fork, please check your email or github notifications |
|
Hi @gbarbieru, |
|
@v-atulyadav working on those screenshots. please note that this PR depends on #13330 which is still failing due to various errors not in our control |











Change(s):
- Creating a Sentinel solution for Bitdefender GravityZone. This solution uses a push-based approach using just a DCR, a DCE, custom table and an App registration with credentials to push data to Sentinel. An analytic rule that uses custom ASIM parsers is used to generate Incidents.
Reason for Change(s):
Version Updated:
Testing Completed:
Checked that the validations are passing and have addressed any issues that are present:
Before going into this topic I want to disclose that development in my team is done on Linux workstations and the available tooling and guides offered by Microsoft kinda lack in this department. Local YAML testing was eventually achieved, but KQL validation failed. Due to time constraints additional effort in making them work Linux environments was abandoned and testing was eventually done on Microsoft Sentinel accounts via end-to-end testing.