Skip to content

Adding new workbook, custom tables, data connector and analytic rules…#12963

Closed
seanmacdonald8 wants to merge 34 commits intoAzure:masterfrom
darktrace:darktrace-li-api
Closed

Adding new workbook, custom tables, data connector and analytic rules…#12963
seanmacdonald8 wants to merge 34 commits intoAzure:masterfrom
darktrace:darktrace-li-api

Conversation

@seanmacdonald8
Copy link
Copy Markdown
Contributor

… for the new log ingestion api-based integration

Required items, please complete

Change(s):

  • Adding a new data connector for log ingestion API method

Reason for Change(s):

  • http data collector will be deprecated soon

Version Updated:

  • N/A

Testing Completed:

  • yes

Checked that the validations are passing and have addressed any issues that are present:

  • Need help

… for the new log ingestion api-based integration
@seanmacdonald8 seanmacdonald8 requested review from a team as code owners October 15, 2025 04:40
@v-shukore v-shukore added Connector Connector specialty review needed Workbook Workbook specialty review needed Analytic Rules labels Oct 15, 2025
@v-kasghosh
Copy link
Copy Markdown
Contributor

v-kasghosh commented Oct 16, 2025

Hey @seanmacdonald8,

I noticed in this PR that you've added a new Workbook, Analytic rules, Custom tables, and Data connector for Darktrace. To move forward, please package the solution as follows:

Also, please add the new Custom tables to the following folder: https://github.com/Azure/Azure-Sentinel/tree/master/.script/tests/KqlvalidationsTests/CustomTables

Also, update the metadata for the workbook at the path below.
https://github.com/Azure/Azure-Sentinel/blob/master/Workbooks/WorkbooksMetadata.json

Let me know if you need any assistance.
Thanks!

@v-kasghosh
Copy link
Copy Markdown
Contributor

Hey @seanmacdonald8, do you have any updates on this?

@v-kasghosh
Copy link
Copy Markdown
Contributor

Hey @seanmacdonald8
We wanted to check on the status of PR 12963. PR is pending for more than 3 weeks. Please let us know if you need any assistance to review this PR. Per our standard operating procedures if no response is received in the next 7 business days, we will close this PR.

Thank you for your cooperation.

@seanmacdonald8
Copy link
Copy Markdown
Contributor Author

Hi @v-kasghosh This is still being worked on and we just added some changes. Please don't close the PR. Will have more updates soon. Thanks.

@seanmacdonald8 seanmacdonald8 requested a review from a team as a code owner November 11, 2025 03:40
@v-kasghosh
Copy link
Copy Markdown
Contributor

Hey @seanmacdonald8

Please package the solution using the V3 tool: https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V3/README.md

Let me know if you need any help. Thanks!

@v-kasghosh
Copy link
Copy Markdown
Contributor

Hey @seanmacdonald8, do you have any updates on this?

@v-kasghosh
Copy link
Copy Markdown
Contributor

Hey @seanmacdonald8
We wanted to check on the status of PR #12963 . PR is pending for more than 30 days. Please let us know if you need any assistance to review this PR. Per our standard operating procedures if no response is received in the next 7 business days, we will close this PR. Thank you for your cooperation.

@seanmacdonald8
Copy link
Copy Markdown
Contributor Author

Hey @seanmacdonald8 We wanted to check on the status of PR #12963 . PR is pending for more than 30 days. Please let us know if you need any assistance to review this PR. Per our standard operating procedures if no response is received in the next 7 business days, we will close this PR. Thank you for your cooperation.

Hi there, please don't close the PR. We are still working on this. Thanks!

@v-kasghosh
Copy link
Copy Markdown
Contributor

v-kasghosh commented Jan 16, 2026

hey @seanmacdonald8 ,

Thank you for your reply. Please let us know once your PR is ready for review.
In the meantime, kindly resolve the conflicts so the validation check can begin.

@v-kasghosh
Copy link
Copy Markdown
Contributor

Hey @seanmacdonald8 , could you please let us know the estimated time you might need to complete this PR?

@dylan-o-sullivan
Copy link
Copy Markdown

After call, moving forward with CCF integration instead of this one

#13523

@v-kasghosh
Copy link
Copy Markdown
Contributor

I'm closing this PR since the changes have been made in this PR #13523

@v-kasghosh v-kasghosh closed this Feb 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Analytic Rules Connector Connector specialty review needed Workbook Workbook specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants