Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Splitting parsers #10479

Open
wants to merge 87 commits into
base: master
Choose a base branch
from
Open
Changes from 1 commit
Commits
Show all changes
87 commits
Select commit Hold shift + click to select a range
d040f31
windows Event and security events split updated parsers
Alekhya0824 May 7, 2024
60dbabe
splited and update parser
Alekhya0824 May 8, 2024
4d2d7b2
updated
Alekhya0824 May 10, 2024
2126f3b
updated
Alekhya0824 May 14, 2024
94bf149
updated parser
Alekhya0824 May 14, 2024
c0a3187
updated
Alekhya0824 May 14, 2024
92a1e62
Updated splited parser
Alekhya0824 May 14, 2024
990fbc5
updated splitted parser
Alekhya0824 May 14, 2024
d173925
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
May 14, 2024
30dfc85
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
May 14, 2024
876d264
Updated splitted Baracuda WAF and Baracuda CEF
Alekhya0824 May 16, 2024
cb218d8
Merge branch 'Splitting_Parsers' of https://github.com/Azure/Azure-Se…
Alekhya0824 May 16, 2024
192cf24
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
May 16, 2024
e0b9b82
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
May 16, 2024
45bcb0c
Updated splitted Baracuda WAF and Baracuda CEF
Alekhya0824 May 16, 2024
5c305c1
Updated splitted Baracuda WAF and Baracuda CEF
Alekhya0824 May 16, 2024
ab26e61
Updated splited Baracuda WAF and Baracuda CEF
Alekhya0824 May 16, 2024
6aa53b5
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
May 16, 2024
ebeed7b
Merge branch 'Splitting_Parsers' of https://github.com/Azure/Azure-Se…
Alekhya0824 May 16, 2024
979a3ca
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
May 16, 2024
22cb932
comments updated
Alekhya0824 May 24, 2024
1eda269
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
May 24, 2024
418ac0c
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
May 24, 2024
749cfc2
added schema and data results files
Alekhya0824 May 27, 2024
45d0f18
updated
Alekhya0824 May 28, 2024
86a7945
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
May 28, 2024
68ec02f
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
May 28, 2024
3cecfae
UPDATED
Alekhya0824 May 28, 2024
d222007
Merge branch 'Splitting_Parsers' of https://github.com/Azure/Azure-Se…
Alekhya0824 May 28, 2024
3ca9dc7
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
May 28, 2024
7d74ae2
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
May 28, 2024
9bdae23
Update ASimRegistry.yaml
Alekhya0824 May 30, 2024
1fdb4f3
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
May 30, 2024
53cd84a
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
May 30, 2024
758e0a7
meraki_CL Syslog Web Session parser
Alekhya0824 May 31, 2024
e7de5ea
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
May 31, 2024
a05e53f
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
May 31, 2024
3a8d509
updated
Alekhya0824 Jun 11, 2024
b8f0851
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
Jun 11, 2024
6d1003b
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jun 11, 2024
1b92d5e
updated schema
Alekhya0824 Jun 11, 2024
301ba02
Merge branch 'Splitting_Parsers' of https://github.com/Azure/Azure-Se…
Alekhya0824 Jun 11, 2024
278d8f4
un-ignore Microsoft.Azure.Sentinel.KustoServices
Alekhya0824 Jun 11, 2024
af960b5
updated
Alekhya0824 Jun 12, 2024
f53176b
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
Jun 12, 2024
d37a75d
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jun 12, 2024
da0c673
updated
Alekhya0824 Jun 12, 2024
2d95cd1
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
Jun 12, 2024
7f95b8c
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jun 12, 2024
42cf5bf
updated
Alekhya0824 Jun 12, 2024
b72d0d0
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
Jun 12, 2024
1404632
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jun 12, 2024
47a40df
changes
vakohl Jul 16, 2024
2abaf27
Merge branch 'master' of https://github.com/Azure/Azure-Sentinel into…
vakohl Jul 16, 2024
98ddf07
updated
Alekhya0824 Jul 18, 2024
6b1d2db
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
Jul 18, 2024
24c33ce
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jul 18, 2024
eb456d3
updated
Alekhya0824 Jul 18, 2024
6082d11
Merge branch 'Splitting_Parsers' of https://github.com/Azure/Azure-Se…
Alekhya0824 Jul 18, 2024
1743161
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jul 18, 2024
05388d7
updated
Alekhya0824 Jul 19, 2024
82c3977
updated
Alekhya0824 Jul 22, 2024
3a920fb
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
Jul 22, 2024
69a750e
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jul 22, 2024
d157338
updated
Alekhya0824 Jul 25, 2024
d5ef4d2
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
Jul 25, 2024
00331d7
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jul 25, 2024
182a6b6
updaTED
Alekhya0824 Jul 25, 2024
ba91732
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Jul 25, 2024
f182a5c
updated
Alekhya0824 Jul 31, 2024
2453ddf
Merge branch 'master' into Splitting_Parsers
Alekhya0824 Aug 1, 2024
a376097
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Aug 1, 2024
b8bf867
updated
Alekhya0824 Aug 1, 2024
ef60968
Merge branch 'Splitting_Parsers' of https://github.com/Azure/Azure-Se…
Alekhya0824 Aug 1, 2024
e9e2de8
Merge remote-tracking branch 'origin/master' into Splitting_Parsers
Aug 1, 2024
e858e53
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Aug 1, 2024
1808190
updated
Alekhya0824 Aug 1, 2024
b19d213
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Aug 1, 2024
97df52a
removing registry changes
vakohl Aug 2, 2024
cffa4c1
fixing conflict
vakohl Aug 2, 2024
8f80093
conflicts
vakohl Aug 2, 2024
fc0db26
Merge branch 'master' of https://github.com/Azure/Azure-Sentinel into…
vakohl Aug 2, 2024
f1ca229
fixing auth changes
vakohl Aug 2, 2024
4a716e4
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Aug 2, 2024
ad34026
IpAddr change
vakohl Aug 2, 2024
068b86e
Merge branch 'Splitting_Parsers' of https://github.com/Azure/Azure-Se…
vakohl Aug 2, 2024
9df4aa2
[ASIM Parsers] Generate deployable ARM templates from KQL function YA…
Aug 2, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
IpAddr change
  • Loading branch information
vakohl committed Aug 2, 2024
commit ad340264a6ebf9c72759290b531f1cf7ba2e1aea
Original file line number Diff line number Diff line change
Expand Up @@ -252,6 +252,8 @@ ParserQuery: |
LogonTarget=TargetDvcHostname
,
Dvc=SrcHostname
,
IpAddr = SrcIpAddr
};
WinLogon(starttime=starttime,endtime=endtime, username_has_any=username_has_any, targetappname_has_any=targetappname_has_any, srcipaddr_has_any_prefix=srcipaddr_has_any_prefix, srchostname_has_any=srchostname_has_any, eventtype_in=eventtype_in, eventresultdetails_in=eventresultdetails_in, eventresult=eventresult, disabled=disabled)

Alekhya0824 marked this conversation as resolved.
Show resolved Hide resolved