Giter Site home page Giter Site logo

Comments (11)

v-muuppugund avatar v-muuppugund commented on June 29, 2024

Hi @Ysuuuuuuuu ,Could you please share more details about the issue,What is solution/Connector and in that if parser share parser details with detailed screen shots

from azure-sentinel.

Ysuuuuuuuu avatar Ysuuuuuuuu commented on June 29, 2024

Hello @v-muuppugund , the solution is similar to https://learn.microsoft.com/en-us/azure/sentinel/connect-logstash-data-connection-rules#create-dcr-resources-for-ingestion-into-a-standard-table.

Part of the logs that will be ingested via logstash are like:
image

This schema is totally different from the schema of standard table SecurityEvent. Then a proper transformkql is needed in DCR to map the fields in the ingested logs to the fields of SecurityEvent.

from azure-sentinel.

v-muuppugund avatar v-muuppugund commented on June 29, 2024

Hi @Ysuuuuuuuu , Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 27Mar24. Thanks!

from azure-sentinel.

Ysuuuuuuuu avatar Ysuuuuuuuu commented on June 29, 2024

Thanks in advance.

from azure-sentinel.

Ysuuuuuuuu avatar Ysuuuuuuuu commented on June 29, 2024

Hello @v-muuppugund , may I get some updates for this ask? Thanks.

from azure-sentinel.

v-muuppugund avatar v-muuppugund commented on June 29, 2024

Hello @v-muuppugund , may I get some updates for this ask? Thanks.

Hi @Ysuuuuuuuu ,Working on further analysis on this issue with Query,will update you

from azure-sentinel.

Ysuuuuuuuu avatar Ysuuuuuuuu commented on June 29, 2024

Thanks. Look forward to your further updates.

from azure-sentinel.

v-muuppugund avatar v-muuppugund commented on June 29, 2024

Hi @Ysuuuuuuuu , Could you please provide couple of time slots for teams meeting on the issue to [email protected] for further troubleshooting.

from azure-sentinel.

v-muuppugund avatar v-muuppugund commented on June 29, 2024

Hi @Ysuuuuuuuu ,As discussed over call today got the data,will update you

from azure-sentinel.

v-muuppugund avatar v-muuppugund commented on June 29, 2024

Hi @Ysuuuuuuuu ,We are working on it ,will update you ,as we are facing some permissions issue during standard conversion,will let you know if needed we can have a call with customer,will update you

from azure-sentinel.

v-muuppugund avatar v-muuppugund commented on June 29, 2024

Hi @Ysuuuuuuuu ,As discussed over teams call today,as per your confirmation as there are no documentation available,we are closing your issue (#10185) as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation

from azure-sentinel.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.