Adding new workbook, custom tables, data connector and analytic rules…#12963
Adding new workbook, custom tables, data connector and analytic rules…#12963seanmacdonald8 wants to merge 34 commits intoAzure:masterfrom
Conversation
… for the new log ingestion api-based integration
|
Hey @seanmacdonald8, I noticed in this PR that you've added a new Workbook, Analytic rules, Custom tables, and Data connector for Darktrace. To move forward, please package the solution as follows:
Also, please add the new Custom tables to the following folder: https://github.com/Azure/Azure-Sentinel/tree/master/.script/tests/KqlvalidationsTests/CustomTables Also, update the metadata for the workbook at the path below. Let me know if you need any assistance. |
|
Hey @seanmacdonald8, do you have any updates on this? |
|
Hey @seanmacdonald8 Thank you for your cooperation. |
|
Hi @v-kasghosh This is still being worked on and we just added some changes. Please don't close the PR. Will have more updates soon. Thanks. |
Extra work from comments
|
Hey @seanmacdonald8 Please package the solution using the V3 tool: https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V3/README.md Let me know if you need any help. Thanks! |
|
Hey @seanmacdonald8, do you have any updates on this? |
|
Hey @seanmacdonald8 |
Hi there, please don't close the PR. We are still working on this. Thanks! |
Dylan/darktrace li work
|
hey @seanmacdonald8 , Thank you for your reply. Please let us know once your PR is ready for review. |
|
Hey @seanmacdonald8 , could you please let us know the estimated time you might need to complete this PR? |
Dylan/darktrace li work
|
After call, moving forward with CCF integration instead of this one |
|
I'm closing this PR since the changes have been made in this PR #13523 |
… for the new log ingestion api-based integration
Required items, please complete
Change(s):
Reason for Change(s):
Version Updated:
Testing Completed:
Checked that the validations are passing and have addressed any issues that are present: