Azure-Sentinel
Azure-Sentinel copied to clipboard
BEC - Stages 2-3 UEBA updates
Required items, please complete
Change(s):
- Added UEBA tables IdentityInfo and BehaviorAnalytics where applicable in all of the BEC scenario stage 2-3 queries.
Reason for Change(s):
- Adding additional UEBA data for context.
Version Updated:
- Yes
- Detections/Analytic Rule templates are required to have the version updated
Testing Completed:
- Yes
Checked that the validations are passing and have addressed any issues that are present:
- Yes
Hello @jannieli please address to @aprakash13 comments
Hello @jannieli @petebryan has requested changes
Hello @jannieli please remove the branch conflicts
Hello @petebryan & @aprakash13 @jannieli has made some changes
Hello @jannieli any updates on the above
Hello @petebryan, @aprakash13 @jannieli has made some changes
Please update the branch from master as well
Hello @jannieli will be investigating this PR, you can expect an update till 14 Jul
Template Id: 99885ff5-00cf-49e8-9452-6de6aba2a5c7 is not valid in Line: 31 col: 8 Errors: The column 'IP_0_Address' must exist on both sides of the join., Code: 'KS145', Severity: 'Error', Location: '1401..1413'
please resolve this issue
Hello @jannieli any updates on above
Hello @jannieli we are waiting for your update, and please also resolve the branch conflicts
Hello @jannieli, Thank you for committing the changes, you can expect an update till 26 Jul 2023