Update Syntax for IPEntity_CloudAppEvents_Updated.yaml Rule#13084
Conversation
Removed a condition that always evaluates to true and causes the rule to fire on revoked and deleted IP addresses within the ThreatIntelIndicators table.
|
Hello @joseph-matter, please package the solution using V3 tool |
|
Hello @v-shukore I added a commit for packaging the solution. |
|
Hi @joseph-matter, please resolve branch conflicts. Thanks! |
|
Hello @v-shukore , the merge conflicts seemed to arise from incrementing the template version. Do I just increment the version of the analytics rule itself or the analtics rule and the template version both? |
|
@microsoft-github-policy-service agree company="Capgemini" |
|
Hi @joseph-matter, to resolve branch conflicts, please pull the latest updates from master and ensure your main template remains in this PR. Thanks! |
|
@v-shukore Merge conflicts resolved |
|
Hi @joseph-matter, amm-ttk is failing because there is a hardcoded URL in the maintemplate at line 951. Please replace or remove that URL from the maintemplate to resolve the issue. Thanks! |
|
@v-shukore Corrected |

Required items, please complete
Change(s):
or isnotempty(NetworkSourceIP)from condition statement.Reason for Change(s):
Version Updated:
Testing Completed:
Checked that the validations are passing and have addressed any issues that are present: