-
Notifications
You must be signed in to change notification settings - Fork 3.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Adding Cribl to Microsoft Azure Solutions Repo #10912
Conversation
fixes for compliance with checks
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated Files to pass the validation.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changes Made:
Corrected Sample files added them into a JSON array
Repaired the mainTemplate.json and createUiDefinition.json to work with validation
Updated Solution_Cribl.json
Added files to 1.0.0.zip file
Updated Parsers and updated their names.
Updated SolutionMetadata.json
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
updated the parser file with the fix to the query field. updated image svg file.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated Solutions under Data Connectors and SolutionMetadta.
Hello @amiracle,
Refer this Solution for more clarification. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updates
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Validated updates to the solution and made changes to be compliant with solution validations.
Hello @amiracle, Please create custom table schema named as CriblInternal_CL and CriblInternal at location |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this Data connector needed. We already have 1 data connector in solution folder.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This data connector was going to be used to connect third party data into Microsoft Sentinel similar to what the syslog connector is doing. The Connector in the Cribl Solution folder is specifically for the data generated by the Cribl Stream solution.
Hello @amiracle, we are waiting for your reply |
Hello @amiracle, Can you please work on the above requested changes. |
This has been completed.
|
All of the custom tables have been added to the repo:
|
@v-prasadboke - I'm trying to decipher the error messages as to why my code is not passing validation. Can you please explain the error codes so that I can properly address them and get this solution added to the repo? |
Hello @amiracle, Can we get on a call for this. You can ping me on teams too if needed - [email protected] |
reference for parser : https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Snowflake/Parsers/Snowflake.yaml V3 tool : C:\GitHub\Azure-Sentinel\Tools\Create-Azure-Sentinel-Solution\V3 |
Change(s):
Cribl Steam Solution added
Added a new folder named "Cribl" in the "Solutions" directory
Created a new Cribl sample files in the Samples Folder
Added Cribl-Logo.svg to "Logos" directory
Reasons for Change(s):
Cribl Stream Solution being added into the Microsoft Azure Sentinel repository.
Version 1.0.0 Added.
Tested and validated Solution file with preview function in Sentinel.
@microsoft-github-policy-service agree [company=“Cribl"]
@microsoft-github-policy-service agree