Skip to content

XBOW Sentinel Connector Update - April 2026#14145

Merged
v-dvedak merged 7 commits into
Azure:masterfrom
GeekMasher:xbow-api-update-april
May 20, 2026
Merged

XBOW Sentinel Connector Update - April 2026#14145
v-dvedak merged 7 commits into
Azure:masterfrom
GeekMasher:xbow-api-update-april

Conversation

@GeekMasher
Copy link
Copy Markdown
Contributor

Required items, please complete

Change(s):

Reason for Change(s):

  • XBOW API changes

Version Updated:

  • Yes

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • See guidance below

@GeekMasher GeekMasher requested review from a team as code owners April 27, 2026 20:22
@v-maheshbh v-maheshbh added the Solution Solution specialty review needed label Apr 28, 2026
@v-shukore v-shukore requested a review from Copilot May 12, 2026 09:12
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates the XBOW Microsoft Sentinel solution to align with XBOW Public API 2026-04-01, including a solution version bump and corresponding content/template updates.

Changes:

  • Bumped solution/package version to 3.0.1 and added release notes entry.
  • Updated the Azure Function connector to use API version 2026-04-01, improve 400 handling, and enrich assessment events (AttackCredits/RecentEvents).
  • Updated analytic rule customDetails keys and incident grouping customDetails accordingly.

Reviewed changes

Copilot reviewed 8 out of 10 changed files in this pull request and generated 7 comments.

Show a summary per file
File Description
Solutions/XBOW/ReleaseNotes.md Adds 3.0.1 release notes describing the API version bump and assessment enrichment.
Solutions/XBOW/Package/mainTemplate.json Updates packaged solution version/description and aligns customDetails/grouping keys with rule updates.
Solutions/XBOW/Data/Solution_Xbow.json Bumps solution version to 3.0.1 in the source data file.
Solutions/XBOW/Data Connectors/AzureFunctionXbow/main.py Updates connector API version, adds response checking for 400s, enriches assessments, refactors sync-state storage.
Solutions/XBOW/Analytic Rules/XbowNewAssetDiscovered.yaml Renames customDetails keys and grouping key (AssetID/OrganizationID).
Solutions/XBOW/Analytic Rules/XbowMediumFindings.yaml Renames customDetails keys and grouping key (FindingID/AssetID/OrganizationID).
Solutions/XBOW/Analytic Rules/XbowLowFindings.yaml Renames customDetails keys and grouping key (FindingID/AssetID/OrganizationID).
Solutions/XBOW/Analytic Rules/XbowCriticalHighFindings.yaml Renames customDetails keys and grouping key (FindingID/AssetID/OrganizationID).

Comment thread Solutions/XBOW/Data Connectors/AzureFunctionXbow/main.py
Comment thread Solutions/XBOW/Data Connectors/AzureFunctionXbow/main.py
Comment thread Solutions/XBOW/Data Connectors/AzureFunctionXbow/main.py
Comment thread Solutions/XBOW/Data Connectors/AzureFunctionXbow/main.py
Comment thread Solutions/XBOW/Data/Solution_Xbow.json Outdated
Comment thread Solutions/XBOW/Data Connectors/AzureFunctionXbow/main.py
Comment thread Solutions/XBOW/Data Connectors/AzureFunctionXbow/main.py
@v-shukore
Copy link
Copy Markdown
Contributor

Hi @GeekMasher, please update the analytic rule version to resolve validation failure and kindly implement the changes recommended by Copilot and commit them once completed. Thanks!

@GeekMasher
Copy link
Copy Markdown
Contributor Author

@v-shukore Any updates on this?

@v-dvedak v-dvedak merged commit 685dd46 into Azure:master May 20, 2026
36 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants