Skip to content

feat!: msgraphforoffice365 sdkified#75

Open
grokas-splunk wants to merge 22 commits intomainfrom
grokas/PAPP-36911-sdkify_msgraphforoffice365
Open

feat!: msgraphforoffice365 sdkified#75
grokas-splunk wants to merge 22 commits intomainfrom
grokas/PAPP-36911-sdkify_msgraphforoffice365

Conversation

@grokas-splunk
Copy link
Contributor

PAPP-36911

‼️ Do not merge after approval (we are waiting to release)

@grokas-splunk grokas-splunk force-pushed the grokas/PAPP-36911-sdkify_msgraphforoffice365 branch from 25f68a8 to a3fb84a Compare January 28, 2026 23:56
@sodle-splunk sodle-splunk force-pushed the grokas/PAPP-36911-sdkify_msgraphforoffice365 branch from c3da88b to cea9c92 Compare March 17, 2026 14:47
sodle-splunk and others added 6 commits March 24, 2026 09:21
When extract_eml is enabled, detect .eml/.msg attachments in forwarded
emails, extract the inner email for the finding, and populate the
FindingEmailReporter with the forwarding email's metadata. Also migrates
from deprecated extract_rfc5322_email_data to extract_email_data.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Mark first_run_max_emails with FieldCategory.INGEST to hide it from
the ES UI, and always use max_containers in the ES poll code path.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Build finding names that include sender/reporter info instead of just
the email subject. Forwarded emails show reporter and original sender;
non-forwarded emails show the sender. Falls back to a formatted UTC
date when the subject is missing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@sodle-splunk sodle-splunk force-pushed the grokas/PAPP-36911-sdkify_msgraphforoffice365 branch from bc3fa0d to d090cb5 Compare March 24, 2026 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants