Skip to content

Update Syntax for IPEntity_CloudAppEvents_Updated.yaml Rule#13084

Merged
v-atulyadav merged 7 commits into
Azure:masterfrom
joseph-matter:joseph-matter/AnalyticsFix
Nov 20, 2025
Merged

Update Syntax for IPEntity_CloudAppEvents_Updated.yaml Rule#13084
v-atulyadav merged 7 commits into
Azure:masterfrom
joseph-matter:joseph-matter/AnalyticsFix

Conversation

@joseph-matter
Copy link
Copy Markdown
Contributor

Required items, please complete

Change(s):

  • Updated Syntax for IPEntity_CloudAppEvents_Updated.yaml.
  • Removed or isnotempty(NetworkSourceIP) from condition statement.
  • Incremented Alert Version

Reason for Change(s):

  • Including the OR condition in this statement causes the entire statement to always evaluate to true and causes the rule to fire on IP Addresses that are revoked or deleted within the ThreatIntelIndicators table.
  • Removed OR condition in line with similar analytics rule so condition works as expected.

Version Updated:

  • Yes

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

Removed a condition that always evaluates to true and causes the rule to fire on revoked and deleted IP addresses within the ThreatIntelIndicators table.
@joseph-matter joseph-matter requested review from a team as code owners November 5, 2025 17:43
@joseph-matter joseph-matter changed the title Joseph matter/analytics fix Update Syntax for IPEntity_CloudAppEvents_Updated.yaml Rule Nov 5, 2025
@v-shukore
Copy link
Copy Markdown
Contributor

@joseph-matter
Copy link
Copy Markdown
Contributor Author

Hello @v-shukore I added a commit for packaging the solution.

@v-shukore
Copy link
Copy Markdown
Contributor

Hi @joseph-matter, please resolve branch conflicts. Thanks!

@joseph-matter
Copy link
Copy Markdown
Contributor Author

Hello @v-shukore , the merge conflicts seemed to arise from incrementing the template version. Do I just increment the version of the analytics rule itself or the analtics rule and the template version both?

@joseph-matter
Copy link
Copy Markdown
Contributor Author

@microsoft-github-policy-service agree company="Capgemini"

@v-shukore
Copy link
Copy Markdown
Contributor

Hi @joseph-matter, to resolve branch conflicts, please pull the latest updates from master and ensure your main template remains in this PR. Thanks!

@joseph-matter
Copy link
Copy Markdown
Contributor Author

@v-shukore Merge conflicts resolved

@v-shukore
Copy link
Copy Markdown
Contributor

Hi @joseph-matter, amm-ttk is failing because there is a hardcoded URL in the maintemplate at line 951. Please replace or remove that URL from the maintemplate to resolve the issue. Thanks!
image

@joseph-matter
Copy link
Copy Markdown
Contributor Author

@v-shukore Corrected

v-shukore
v-shukore previously approved these changes Nov 20, 2025
@v-atulyadav v-atulyadav merged commit 7721e0b into Azure:master Nov 20, 2025
35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants