Skip to content

Refined BloodHound Enterprise Connector: Update documentation, metric queries, and Azure Function source#13922

Merged
v-atulyadav merged 4 commits into
Azure:masterfrom
metron-labs:bloodhound
May 6, 2026
Merged

Refined BloodHound Enterprise Connector: Update documentation, metric queries, and Azure Function source#13922
v-atulyadav merged 4 commits into
Azure:masterfrom
metron-labs:bloodhound

Conversation

@omkarj-metron
Copy link
Copy Markdown
Contributor

Pull Request Description

Change(s):

  • Enhanced Documentation: Improved API credential instructions to simplify the onboarding process for new users.
  • Updated Deployment Source: Modified the zip file URL to point to the latest stable version hosted in the official Azure Sentinel repository.
  • Optimized Metric Queries: Refined the logic for metric queries to provide more accurate data visualization and performance.
  • Template Restructuring: Added a new empty array template within mainTemplate.json to ensure a more robust and scalable deployment structure.
  • Connector Logic: Updated the ingestion method to leverage Azure Functions as a data connector for improved reliability and data fetching via REST API.

Reason for Change(s):

  • User Experience: To reduce deployment friction by providing clearer steps and ensuring the solution points to the most current, verified source files and deployment instructions.

Version Updated:

  • Yes

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

…, improve API credential instructions, and modify metric queries. Changed zip file URL to point to the latest version on the Azure Sentinel repository. Added a new empty array template in mainTemplate.json for better structure.
@v-atulyadav v-atulyadav added the Solution Solution specialty review needed label Mar 26, 2026
@omkarj-metron omkarj-metron marked this pull request as ready for review April 29, 2026 06:53
@omkarj-metron omkarj-metron requested review from a team as code owners April 29, 2026 06:53
@v-shukore
Copy link
Copy Markdown
Contributor

Hi @omkarj-metron, please resolve below validation failure. Thanks
image

… to update the schema for posture history data to eliminate kql validation error.
@omkarj-metron omkarj-metron requested a review from a team as a code owner May 4, 2026 07:38
@omkarj-metron
Copy link
Copy Markdown
Contributor Author

Hi @v-shukore,
I’ve fixed the KQL validation issue. Can you please take a quick look & re-run the pipeline when you have a moment?

@v-shukore
Copy link
Copy Markdown
Contributor

Hi @omkarj-metron, again kql validation is failing due to column is not present into that table schema make sure all columns are present into it. Thanks!
image

…ineData_CL.json, BHEAuditLogsData_CL.json, and BHETierZeroAssetsData_CL.json for improved data tracking.
@omkarj-metron
Copy link
Copy Markdown
Contributor Author

Hi @v-shukore,
I’ve fixed the KQL validation issue regarding missing TimeGenerated field. Can you please take a quick look?

@v-atulyadav v-atulyadav merged commit 05f7930 into Azure:master May 6, 2026
33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants