Skip to content

Update IPEntity_AppServiceHTTPLogs.yaml#12870

Merged
v-atulyadav merged 3 commits into
Azure:masterfrom
TommyJohansson:patch-2
Nov 19, 2025
Merged

Update IPEntity_AppServiceHTTPLogs.yaml#12870
v-atulyadav merged 3 commits into
Azure:masterfrom
TommyJohansson:patch-2

Conversation

@TommyJohansson
Copy link
Copy Markdown
Contributor

Template was broken, added missing column.

Required items, please complete

Change(s):

  • Added missing column in IPEntity_AppServiceHTTPLogs.yaml

Reason for Change(s):

  • Template was broken

Version Updated:

  • Yes

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Edited local template and uploaded it i the UI without issues

Template was broken, added missing column.
@v-maheshbh
Copy link
Copy Markdown
Contributor

HI @TommyJohansson Kindly accept CLA.
thanks!

@TommyJohansson
Copy link
Copy Markdown
Contributor Author

@microsoft-github-policy-service agree

@TommyJohansson
Copy link
Copy Markdown
Contributor Author

@v-maheshbh Sure, but i think my comment was not the correct way to accept the CLA. Can you please give me some guidance on where/how i accept it ?

@v-maheshbh
Copy link
Copy Markdown
Contributor

HI @TommyJohansson Try this @microsoft-github-policy-service agree company="Company name" add in comment.

Thanks!

@TommyJohansson
Copy link
Copy Markdown
Contributor Author

@microsoft-github-policy-service agree company="SentorSecurity"

@TommyJohansson
Copy link
Copy Markdown
Contributor Author

@v-maheshbh Guess that didnt work.

@TommyJohansson
Copy link
Copy Markdown
Contributor Author

@v-maheshbh How to we fix this ?

@v-maheshbh
Copy link
Copy Markdown
Contributor

Hi @TommyJohansson Kindly package solution.
Thanks!

@v-shukore v-shukore added the Solution Solution specialty review needed label Oct 8, 2025
@v-maheshbh
Copy link
Copy Markdown
Contributor

Hi @TommyJohansson Kindly check above comment.

Thanks!

@TommyJohansson
Copy link
Copy Markdown
Contributor Author

@v-maheshbh Sorry this is my first pull-request and i don't know what that mean or what i should do?

@v-maheshbh
Copy link
Copy Markdown
Contributor

Hi @TommyJohansson KIndly package solution using v3 tool. You can find the V3 tool here:
https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V3/README.md

thanks!

@SteveBurkettNZ
Copy link
Copy Markdown

Concur with Tommy's change here, the existing analytics rule for AppServiceHTTPLogs wouldn't save in Microsoft Sentinel with an error:

Failed to save analytics rule 'TI map IP entity to AppServiceHTTPLogs'. BadRequest:Error in AlertDetailsOverride: The given column 'AlertPriority' does not exist.

Adding AlertPriority to the final project line allowed me to save it.

@v-maheshbh, I'd expect that a Microsoft employee (or v- user) should be doing the final packaging here, I gather that Tommy is just a member of the general public, like myself?

@TommyJohansson
Copy link
Copy Markdown
Contributor Author

@SteveBurkettNZ Yeah im just a security analyst and not a Microsoft employee, not a developer either 😅

That step of creating a "package solution" was a bit hard to grasp, maybe i need try it again.

@v-maheshbh
Copy link
Copy Markdown
Contributor

Hi @TommyJohansson
This Threat Intelligence solution will be deprecated in the future. Since we now have the updated solution, Threat Intelligence (NEW), [https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Threat%20Intelligence%20(NEW)]
please apply the same changes to the new solution as well. Also, is there any reason why the changes were applied to the old solution?

Thanks!

@TommyJohansson
Copy link
Copy Markdown
Contributor Author

I have created a new pull-request for the "NEW" solution, it had the same issue.

Bumped solution version to 3.1.3 across templates and metadata. Updated analytic rule versions and entity mappings, removed one analytic rule, and revised UI definition to reflect 52 analytic rules. Added new package zip for 3.1.3 and updated documentation and connector descriptions for clarity and Microsoft Entra ID terminology.
@v-atulyadav v-atulyadav merged commit 0dff59f into Azure:master Nov 19, 2025
34 of 35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants