Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Dns domain solution

Open vakohl opened this issue 3 years ago • 5 comments

Required items, please complete

Change(s):

  • Created new solution for DNS

Reason for Change(s):

  • New Solution

Version Updated:

  • Required only for Detections/Analytic Rule templates
  • See guidance below

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • See guidance below

vakohl avatar Dec 30 '22 08:12 vakohl

Hey @vakohl, please add the missing connector ids (e.g. ISCBind) used for Analytic rules in this file, thanks.

v-sabiraj avatar Dec 30 '22 12:12 v-sabiraj

@vakohl, please add the table schema in this folder, If table is already available please update the column names, thanks.

v-sabiraj avatar Dec 30 '22 13:12 v-sabiraj

Hey @vakohl, please add the missing connector ids (e.g. ISCBind) used for Analytic rules in this file, thanks.

done

vakohl avatar Jan 03 '23 11:01 vakohl

@vakohl, can you please revert the changes made for input folder. Also please check on the offerid as discussed. Thanks.

v-sabiraj avatar Jan 09 '23 04:01 v-sabiraj

@vakohl, please add the table schema in this folder, If table is already available please update the column names, thanks.

Rule validations were failing because of the KQL validations. Since we have Watchlist used in all Analytics rules, I've added all analytic rule templates under skipKQLValidation group

vakohl avatar Jan 11 '23 10:01 vakohl

Hey @vakohl, let me discuss the failing arm-ttk checks with @mkchiliveri. Thanks.

v-sabiraj avatar Jan 18 '23 05:01 v-sabiraj

Hey @vakohl, let me discuss the failing arm-ttk checks with @mkchiliveri. Thanks.

thanks, can you help fixing this?

vakohl avatar Jan 18 '23 09:01 vakohl

@vakohl , can you please update the branch from master as the checks are stopped running, thanks.

v-sabiraj avatar Jan 20 '23 05:01 v-sabiraj

@vakohl, just adding to infom that it will remain open till offer is in private preview. Thanks.

v-sabiraj avatar Jan 27 '23 06:01 v-sabiraj

@vakohl, just adding to infom that it will remain open till offer is in private preview. Thanks.

sounds good. [We need to wait for Private prevew to complete. I will confirm when we can merge this into Master]

vakohl avatar Jan 31 '23 06:01 vakohl

@vakohl, can you please resolve the conflicts, thanks.

v-sabiraj avatar Mar 10 '23 06:03 v-sabiraj

Hi @devikamehra When you get chance, please help approving this PR. This was already reviewed by Ofer but I made few grammatical changes in the rule name and description. The same version is in Private Preview since feb last week, no changes done since then.

vakohl avatar Mar 16 '23 09:03 vakohl

@v-sabiraj Can you help merging this PR to master?

vakohl avatar Mar 16 '23 12:03 vakohl

@vakohl, sure.

v-sabiraj avatar Mar 17 '23 06:03 v-sabiraj