Skip to content

Update the IPEntity_DuoSecurity Analytic Rule for Threat Intelligence (NEW)#13774

Merged
v-atulyadav merged 4 commits intomasterfrom
v-kasghosh/issue-number/13701
Mar 17, 2026
Merged

Update the IPEntity_DuoSecurity Analytic Rule for Threat Intelligence (NEW)#13774
v-atulyadav merged 4 commits intomasterfrom
v-kasghosh/issue-number/13701

Conversation

@v-kasghosh
Copy link
Copy Markdown
Contributor

Change(s):

  • Update the IPEntity_DuoSecurity Analytic Rule

Reason for Change(s):

Version Updated:

  • solution - 3.0.15
  • Rule - 1.0.10

@v-kasghosh v-kasghosh requested review from a team as code owners March 9, 2026 08:24
@contentautomationbot
Copy link
Copy Markdown

Hello how are you I am GitHub bot
😀😀
I see that you changed templates under the detections/analytic rules folder. Did you remember to update the version of the templates you changed?
If not, and if you want customers to be aware that a new version of this template is available, please update the version property of the template you changed.

@v-atulyadav v-atulyadav added the Solution Solution specialty review needed label Mar 9, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Threat Intelligence (NEW) solution to reflect the latest changes to the Duo Security IP entity analytic rule (closing #13701), including version bumps and installer UI text updates.

Changes:

  • Added a 3.0.15 release note entry for the updated DuoSecurity analytic rule.
  • Updated the solution installer UI definition text for the Threat Intelligence (NEW) data connectors section.
  • Updated the IPEntity_DuoSecurity analytic rule query to use the CiscoDuo table/fields and bumped the rule version to 1.0.10.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 7 comments.

File Description
Solutions/Threat Intelligence (NEW)/ReleaseNotes.md Adds release note entry for solution version 3.0.15.
Solutions/Threat Intelligence (NEW)/Package/createUiDefinition.json Reworks the data connectors UI text (currently introduces repeated/duplicated content).
Solutions/Threat Intelligence (NEW)/Analytic Rules/IPEntity_DuoSecurity.yaml Updates the rule query to the new Cisco Duo schema and bumps rule version.

Comment thread Solutions/Threat Intelligence (NEW)/Package/createUiDefinition.json
Comment thread Solutions/Threat Intelligence (NEW)/Package/createUiDefinition.json
Comment thread Solutions/Threat Intelligence (NEW)/Package/createUiDefinition.json
Comment thread Solutions/Threat Intelligence (NEW)/Package/createUiDefinition.json
Comment thread Solutions/Threat Intelligence (NEW)/Package/createUiDefinition.json
Comment thread Solutions/Threat Intelligence (NEW)/Package/createUiDefinition.json
@v-atulyadav v-atulyadav merged commit e54038a into master Mar 17, 2026
36 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CiscoDuo TI rule fails to deploy due to wrong table name DuoSecurityAuthentication_CL

4 participants