Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Initial Release of Dragos Sentinel Solution #11582

Open
wants to merge 19 commits into
base: master
Choose a base branch
from

Conversation

dragosinc-sentinel
Copy link

Change(s):

  • Adding new Dragos Sentinel Solution

Reason for Change(s):

  • Initial release of Dragos Sentinel Solution

Version Updated:

  • No. Initial release.

Testing Completed:

  • Yes. Tested CCP data connector and parsers used to process CEF data sent via AMA

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

@dragosinc-sentinel dragosinc-sentinel marked this pull request as ready for review December 19, 2024 02:01
@dragosinc-sentinel dragosinc-sentinel requested review from a team as code owners December 19, 2024 02:01
@dragosinc-sentinel
Copy link
Author

@microsoft-github-policy-service agree company="Dragos Inc."

@v-prasadboke v-prasadboke added New Solution For new Solutions which are new to Microsoft Sentinel Parser Parser specialty review needed labels Dec 19, 2024
@dragosinc-sentinel
Copy link
Author

I seem to be failing some KQL validations, but the error messages are not helpful. I have been unable to figure out what the issue is as the KQL queries validate and run properly when deployed in Sentinel. There is also an issue with the Analytic Rule that may be related to KQL. Appreciate any help you can provide.

@dragosinc-sentinel
Copy link
Author

Resolved the KQL issues and also refactored core Sentinel validations code to support SentinelEntities, this enabled automated validations to pass

@dragosinc-sentinel
Copy link
Author

@v-prasadboke or @v-shukore could you please provide some feedback on this PR. Its been a few weeks and we are hoping to get this merged soon.

@v-shukore
Copy link
Contributor

Hi @dragosinc-sentinel, sorry for the delay in response. Already working on it. Will update you soon. Thanks!!

@dragosinc-sentinel
Copy link
Author

@v-prasadboke and @v-shukore could you please provide and update or an estimated completion date? I need to coordinate with my colleagues as part of the larger release process that involves this PR along with the Microsoft Partner Center.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
New Solution For new Solutions which are new to Microsoft Sentinel Parser Parser specialty review needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants