update parser with new attributes and fixes for some prefixes issues
Required items, please complete
Change(s):
- Updated the parser for Vectra Stream: VectraStream_function.kql
Reason for Change(s):
- Missing attributes (new attributes released in Vectra's product)
- Some attributes did not have the right prefix (e.g. sometimes identified as string, sometimes as digit)
Testing Completed:
- Yes
Checked that the validations are passing and have addressed any issues that are present:
@danymello : Could you please resolve the below errors

@danymello : Please fix above commented errors still we are getting same errors. This PR is depending on #5816 please fix errors asap. Thanks
@danymello : Please fix above commented errors still we are getting same errors. and let us know
Hi @danymello Please fix the comments. Thanks
Hi @danymello Please fix the comments. Thanks
Hi @danymello Please fix the comments. Thanks
@v-spadarthi , I know about the duplicate but I dont know how to handle this scenario. Depending on the value, it is not recognized as the same type every time. To handle the different scenarios, I duplicate entries. Please advise on how to handle this case.
@v-spadarthi , could you please update ??
@danymello : We will check with internal team and let you know the update.
@danymello : Could you please have a look and let us know if it meets your criteria, we are providing the updated parser VectraStreamParser.txt to you. Thanks!!
Hi @danymello Please let us know if the provided parser can help or do you need any help over there. Thanks
@v-mchatla , updated parser I just pushed should be good to go
Hi @danymello, We will have a look and let you know if anything is missing. Thank you!
@danymello : Please resolve below error

@danymello : Please resolve below error
I don't see the same issue. columns exist in my setup

@danymello / @fgu-vectra : Could you please share the updated sample data and will ingest and test it again the parser. Thanks!
@danymello / @fgu-vectra : Could you please share the updated sample data and will ingest and test it again the parser. Thanks!
@danymello / @fgu-vectra : Please share the updated sample data.
@danymello / @fgu-vectra : Please share the updated sample data.
please take a look at the new samples added.
Thanks for sharing the sample data.
I have ingested sample data
Parser tested again working fine
But,This PR is depending on https://github.com/Azure/Azure-Sentinel/pull/5816 as well please fix below

Thanks for sharing the sample data. I have ingested sample data
Parser tested again working fine
But,This PR is depending on #5816 as well please fix below
added smtp metadata sample which has the "date" attribute
@danymello : Thanks for sharing the updated sample data.
Please fix the validation error
Sample data
Parser
Workbook also fine
Once fix the validation error good to merge. Thanks
@danymello : Please resolve the validation errors. Thanks!
@danymello : Please resolve the validation errors. Thanks!
email has ben sanitized
@danymello : Thanks for the fixing the validation error.
Ingested sample data again
