Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Update Archive Log PS1 to work with Azure Government

Open kenrward opened this issue 3 years ago • 14 comments

Required items, please complete

Change(s):

  • Updated the Archive Powershell in the the Tools/Archive-Log-Tool folder to allow this powershell script to connect to Azure Government. This required a new parameter, AzEnvironment to allow users to specify the environment and change the API endpoints. This also required a change to the Connect-AzAccount on line 513 to UseDeviceAuthentication.

Reason for Change(s):

  • The original script did not work for Azure Government as written.

Version Updated:

  • No

Testing Completed:

  • Yes. Tested in BOTH AzureCloud and AzureUSGovernment

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

Guidance <- remove section before submitting


Before submitting this PR please ensure that you have read the following sections and filled out the changes, reason for change and testing complete sections:

Thank you for your contribution to the Microsoft Sentinel Github repo.

Details of the code changes in your submitted PR. Providing descriptions for pull requests ensures there is context to changes being made and greatly enhances the code review process. Providing associated Issues that this resolves also easily connects the reason.

Change(s):

  • Updated the Archive Powershell in the the Tools/Archive-Log-Tool folder to allow this powershell script to connect to Azure Government. This required a new parameter, AzEnvironment to allow users to specify the environment and change the API endpoints. This also required a change to the Connect-AzAccount on line 513 to UseDeviceAuthentication.

Reason for Change(s):

  • The original script did not work for Azure Government as written.

Version updated:

  • No
  • Detections/Analytic Rule templates are required to have the version updated

The code should have been tested in a Microsoft Sentinel environment that does not have any custom parsers, functions or tables, so that you validate no incorrect syntax and execution functions properly. If your submission requires a custom parser or function, it must be submitted with the PR.

Testing Completed:

  • Yes. Tested in BOTH AzureCloud and AzureUSGovernment

Note: If updating a detection, you must update the version field.

Before the submission has been made, please look at running the KQL and Yaml Validation Checks locally. https://github.com/Azure/Azure-Sentinel#run-kql-validation-locally

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

Note: Let us know if you have tried fixing the validation error and need help.

References:


kenrward avatar Jun 14 '22 15:06 kenrward

CLA assistant check
All CLA requirements met.

ghost avatar Jun 14 '22 15:06 ghost

@sreedharande, the zip was updated at the same time. The changelog (c40cf5f) should show a commit for it and the script at the same time. It's a little messy bc I committed some of the log files and deleted everything before doing a clean commit.

kewar-msft avatar Jun 15 '22 00:06 kewar-msft

@sreedharande : Please review and provide your signoff. Thanks!!

v-spadarthi avatar Sep 02 '22 07:09 v-spadarthi

@sreedharande : Please review and provide your signoff. Thanks!!

v-spadarthi avatar Sep 07 '22 09:09 v-spadarthi

@sreedharande : Please review and provide your signoff. Thanks!!

v-spadarthi avatar Sep 08 '22 07:09 v-spadarthi

@sreedharande : Please review and provide your signoff. Thanks!!

v-spadarthi avatar Sep 14 '22 12:09 v-spadarthi

@sreedharande : Please review and provide your signoff. Thanks!!

v-marimanda avatar Sep 20 '22 05:09 v-marimanda

@sreedharande Please take a look once and provide your sign off. thanks!!!

v-marimanda avatar Sep 22 '22 13:09 v-marimanda

@sreedharande Please take a look once again and provide your sign off. thanks!!!

v-spadarthi avatar Sep 28 '22 04:09 v-spadarthi

@sreedharande Please take a look once again and provide your sign off. thanks!!!

v-marimanda avatar Sep 30 '22 05:09 v-marimanda

@sreedharande Please take a look once again and provide your sign off. thanks!!!

v-marimanda avatar Oct 04 '22 05:10 v-marimanda

@sreedharande Please take a look once again and provide your sign off. thanks!!!

v-amolpatil avatar Oct 07 '22 05:10 v-amolpatil

@sreedharande Please take a look once again and provide your sign off. thanks!!!

v-marimanda avatar Oct 11 '22 11:10 v-marimanda

@sreedharande Please take a look once again and provide your sign off. thanks!!!

v-marimanda avatar Oct 14 '22 05:10 v-marimanda

Hi @sreedharande, Author has incorporated the changes requested. Can you please review once again and provide your feedback. Thanks

v-mchatla avatar Oct 18 '22 20:10 v-mchatla