Skip to content

Cite the ingest source for the uppercase behaviour - #3

Merged
saluc28 merged 2 commits into
mainfrom
claude/beautiful-wu-a393c0
Aug 5, 2026
Merged

Cite the ingest source for the uppercase behaviour#3
saluc28 merged 2 commits into
mainfrom
claude/beautiful-wu-a393c0

Conversation

@saluc28

@saluc28 saluc28 commented Aug 4, 2026

Copy link
Copy Markdown
Owner
  • Drop an unverified claim about MSSQLHound's schema
  • Cite the ingest source for the uppercase behaviour

saluc28 added 2 commits August 5, 2026 01:05
The note called it the only public reference implementation of an extension
definition schema. bloodhound-kube publishes one too, in config/schema.json,
outside internal/. The reason to pin against MSSQLHound is that its schema
comes from the people who define the format, not that it is the only one.
The note rested on an observation against a running instance. ConvertGenericNode
uppercases the id on the generic ingest path, at convertors.go:36 in v9.5.1, and
the comment beside the line calls it a BloodHound convention.

The use_raw_object_id flag would keep the original case, but its migration ships
it with enabled and user_updatable both false, so callers cannot turn it on.
@saluc28
saluc28 merged commit 7a6a681 into main Aug 5, 2026
9 checks passed
@saluc28
saluc28 deleted the claude/beautiful-wu-a393c0 branch August 5, 2026 19:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant