Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Added workbook for AI Vectra Stream solution

Open jayeshprajapaticrest opened this issue 2 years ago • 19 comments

Required items, please complete

Change(s):

  • Added workbook for AIVectraStream

Reason for Change(s):

  • New implementation

Version Updated:

  • Initial Version

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

jayeshprajapaticrest avatar Aug 04 '22 10:08 jayeshprajapaticrest

@jayeshprajapaticrest : Please fix the below validation errors In Connection section we are getting below error please see the below screenshot image image In DNS section we are getting below error please see the below screenshot image In Host section we are getting below error please see the below screenshot image

v-spadarthi avatar Aug 07 '22 13:08 v-spadarthi

@jayeshprajapaticrest : Please fix the below validation errors In Connection section we are getting below error please see the below screenshot image image In DNS section we are getting below error please see the below screenshot image @v-spadarthi This issue is because of no data available in dropdown filter within selected time range. Details : If there is no data available in "Service" and "Query Type" dropdown filter within selected time range then by default "All" will be selected in UI and as there is no data available it will display that we must need to set the filter value which will be used in all the implemented queries. We are unable to handle this as no data available in the selected time range.

But if you select time range to more than 3 days then the data is available above filter and also in panels.

In Host section we are getting below error please see the below screenshot image @v-spadarthi This issue is because of "Date" is not available in the current version of parser. The PR has been raised with the latest updated parser with the "Date" implementation, so once this is merged the above error might gets resolved automatically. Latest parser PR link : https://github.com/Azure/Azure-Sentinel/pull/5825

jayeshprajapaticrest avatar Aug 08 '22 07:08 jayeshprajapaticrest

@jayeshprajapaticrest : Please fix the below validation errors In Connection section we are getting below error please see the below screenshot image image In DNS section we are getting below error please see the below screenshot image @v-spadarthi I have fixed the above validation errors could you please confirm it and let us know if it works or not?

jayeshprajapaticrest avatar Aug 09 '22 09:08 jayeshprajapaticrest

@v-spadarthi Is there any updates on above PR merging request as we have fixed the required information suggested by you?

jayeshprajapaticrest avatar Aug 17 '22 14:08 jayeshprajapaticrest

@v-spadarthi Is there any updates on above PR merging request?

jayeshprajapaticrest avatar Sep 05 '22 06:09 jayeshprajapaticrest

@jayeshprajapaticrest : As this PR having dependency on #5825, Please fix the issues in the PR .

v-spadarthi avatar Sep 05 '22 06:09 v-spadarthi

image

Hello,

please fix the issue .

v-laanjana avatar Sep 08 '22 09:09 v-laanjana

image

Hello,

please fix the issue .

@v-laanjana Sorry, But is it fine it remains as it is as this is the part of requirements?

To view the data of Host, user must need to provide host name. If user provide * as input in it will display all host name data.

image

jayeshprajapaticrest avatar Sep 08 '22 11:09 jayeshprajapaticrest

@v-laanjana Please look into this.

NikTripathi avatar Sep 08 '22 19:09 NikTripathi

@NikTripathi we are checking .

v-laanjana avatar Sep 23 '22 03:09 v-laanjana

@jayeshprajapaticrest : As this PR having dependency on https://github.com/Azure/Azure-Sentinel/pull/5825, Please fix the issues in the PR .

v-spadarthi avatar Sep 28 '22 02:09 v-spadarthi

@jayeshprajapaticrest : As this PR having dependency on https://github.com/Azure/Azure-Sentinel/pull/5825, Please fix the issues in the PR .

v-laanjana avatar Sep 30 '22 05:09 v-laanjana

@jayeshprajapaticrest : As this PR having dependency on #5825, Please fix the issues in the PR . @v-laanjana OK Will ask PR raised person to fix it as early as possible so we can proceed with this.

jayeshprajapaticrest avatar Sep 30 '22 06:09 jayeshprajapaticrest

OK Will ask PR raised person to fix it as early as possible so we can proceed with this.

Thanks for the update. Please keep us posted on the same.

v-mchatla avatar Oct 04 '22 19:10 v-mchatla

@jayeshprajapaticrest Do we have any update on this sir? Thanks.

NikTripathi avatar Oct 07 '22 04:10 NikTripathi

@jayeshprajapaticrest Do we have any update on this sir? Thanks. @NikTripathi They already have updated on the dependent PR(#5825) and waiting for the response from reviewer. image

jayeshprajapaticrest avatar Oct 07 '22 05:10 jayeshprajapaticrest

@jayeshprajapaticrest : Still we are getting the error and requested the updated sample data to test the Parser.

v-spadarthi avatar Oct 12 '22 05:10 v-spadarthi

@jayeshprajapaticrest : We requested the updated sample data.

v-spadarthi avatar Oct 17 '22 07:10 v-spadarthi

@jayeshprajapaticrest : We requested the updated sample data.

@v-spadarthi OK Thanks for the update. We need to wait till they provide data and merge that PR(#5825)

jayeshprajapaticrest avatar Oct 17 '22 08:10 jayeshprajapaticrest

image image image image Above all are fine @Jayeshprajapaticrest: Still, we are getting below error after #5825 sample data provided and ingested also, please check and fix it. In Host section we are getting below please fix it image image

v-spadarthi avatar Oct 18 '22 06:10 v-spadarthi

Above all are fine @jayeshprajapaticrest: Still, we are getting below error after #5825 sample data provided and ingested also, please check and fix it. In Host section we are getting below please fix it image

image

@v-spadarthi As I checked on the parser they are going to commit in the PR(5825), there is a column with the name "date" is available. I don't know why it would not be available in the provided sample data.

jayeshprajapaticrest avatar Oct 18 '22 09:10 jayeshprajapaticrest

@jayeshprajapaticrest : Thanks for sharing the updated sample data we ingested and tested working fine. image Anyway we need to re-package this once #5825 validation error fixes we can good to merge. Thanks!

v-spadarthi avatar Oct 19 '22 08:10 v-spadarthi

@jayeshprajapaticrest : Thanks for sharing the updated sample data we ingested and tested working fine. image Anyway we need to re-package this once #5825 validation error fixes we can good to merge. Thanks!

@v-spadarthi Thanks for the Update.

jayeshprajapaticrest avatar Oct 19 '22 09:10 jayeshprajapaticrest

@jayeshprajapaticrest : The https://github.com/Azure/Azure-Sentinel/pull/5825 validation error fixed now all looks good

v-spadarthi avatar Oct 21 '22 05:10 v-spadarthi

By mistakenly closed sorry for that we are good to merge

v-spadarthi avatar Oct 21 '22 05:10 v-spadarthi

@v-spadarthi Thanks for the support. Can you please let me know approx how much time it would take to publicly available of this workbook in Azure portal?

jayeshprajapaticrest avatar Oct 21 '22 05:10 jayeshprajapaticrest