secRMM version 3.0.0 adds 'Analytic Rules' to the Microsoft Sentinel …#12959
Conversation
|
Hi @anthonylamark, |
|
Hi, |
|
Hi @anthonylamark, https://github.com/Azure/Azure-Sentinel/wiki/Query-Style-Guide |
|
Hi @anthonylamark, |
|
I have resubmitted the analytic rule again (removed the properties line). |
|
Hi @anthonylamark.
|
|
|
Hi @anthonylamark, I’m still seeing the 2.0.0 package along with 2.0.1 and 3.0.0. We need to retain only one commit, which should be for 3.0.0. Additionally, please ensure that the workbook metadata is updated at the following location: Additionally, the following validations are failing: |
…update analytic rule yaml
|
Hi,
|
|
Hi @anthonylamark,
|
updated url (I guess is the domain validataion failing but not 100% sure) in Package\mainTemplate.json and Data Connectors\SquadraTechnologies.SecRMM.json
|
Based on the latest comment from code owner v-atulyadav: There are still a few places where the API version needs to be upgraded. Please refer to the screenshot below for reference. Additionally, the domain validation is failing. The following 2 files have been modified: In Package\mainTemplate.json:
In Data Connectors\SquadraTechnologies.SecRMM.json |
|
Hi @anthonylamark, |
|
Hi v-atulyadav, |





The Microsoft Sentinel team informed Squadra Technologies that the 'Microsoft Sentinel secRMM' solution was not compliant because it was missing a 'Microsoft Sentinel Analytic Rule'. This pull request contains the secRMM Analytic Rule that was required.
Required items: There are no requirements for this change.
Change(s):
Reason for Change(s):
Version Updated: Bumped the version from 2.0.1 to 3.0.0
Testing Completed:
Checked that the validations are passing and have addressed any issues that are present: