Varun Kohli

Results 39 comments of Varun Kohli

Will be including these changes once we new filter changes are applied for all authentication parsers. changing this PR to draft state until then.

@azurekid Can you please add description for why we need this? For every schema we already have deploy to azure feature https://github.com/Azure/Azure-Sentinel/tree/master/Parsers/ASimDns

@azurekid Customers can deploy the existing ASIM parser for each schema, e.g. through the link I shared. ![image](https://github.com/Azure/Azure-Sentinel/assets/97222872/d15c6470-2819-478f-be5d-271396668f1f) We make every parser ARM deployable as soon we get them merged...

@azurekid Sounds good. I'll take a look.

@azurekid sorry for late response on this PR. I tried to deploy template generated by this script. Seems there's something wrong with the script. The output json templates fails during...

> No worries, > > Can you please share an error message or the generated template so I can see where it goes wrong. Will also check it today and...

@azurekid I still couldn't deploy. Used this command: .\ConvertFrom-ASim.ps1 -FilesPath "C:\Users\vimAuditEventMicrosoftExchangeAdmin365.yaml" ![image](https://github.com/Azure/Azure-Sentinel/assets/97222872/d2cccd3d-ce4f-4b42-8f30-6bcd3d2f6ffe)

> Hey @vakohl, please add the missing connector ids (e.g. ISCBind) used for Analytic rules in [this file](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/.script/tests/detectionTemplateSchemaValidation/ValidConnectorIds.json), thanks. done

> @vakohl, please add the table schema in this [folder](https://github.com/Azure/Azure-Sentinel/tree/master/.script/tests/KqlvalidationsTests/CustomTables), If table is already available please update the column names, thanks. Rule validations were failing because of the KQL validations....

> Hey @vakohl, let me discuss the failing arm-ttk checks with @mkchiliveri. Thanks. thanks, can you help fixing this?