diff --git a/.github/workflows/convertKqlFunctionYamlToArmTemplate.yaml b/.github/workflows/convertKqlFunctionYamlToArmTemplate.yaml index 37ecc164f8b..0aa38dbf804 100644 --- a/.github/workflows/convertKqlFunctionYamlToArmTemplate.yaml +++ b/.github/workflows/convertKqlFunctionYamlToArmTemplate.yaml @@ -15,6 +15,7 @@ on: - 'Parsers/ASimRegistryEvent/Parsers/**' - 'Parsers/ASimUserManagement/Parsers/**' - 'Parsers/ASimDhcpEvent/Parsers/**' + - 'Parsers/ASimAlertEvent/Parsers/**' env: GITHUB_APPS_ID: "${{ secrets.APPLICATION_ID }}" diff --git a/.script/getModifiedASimSchemas.ps1 b/.script/getModifiedASimSchemas.ps1 index c2db14a067e..279d0801fc5 100644 --- a/.script/getModifiedASimSchemas.ps1 +++ b/.script/getModifiedASimSchemas.ps1 @@ -1,5 +1,5 @@ function getModifiedAsimSchemas() { - $schemas = ("ASimDns", "ASimWebSession", "ASimNetworkSession", "ASimProcessEvent", "ASimAuditEvent", "ASimAuthentication", "ASimFileEvent", "ASimRegistryEvent","ASimUserManagement","ASimDhcpEvent") + $schemas = ("ASimDns", "ASimWebSession", "ASimNetworkSession", "ASimProcessEvent", "ASimAuditEvent", "ASimAuthentication", "ASimFileEvent", "ASimRegistryEvent","ASimUserManagement","ASimDhcpEvent","ASimAlertEvent") $modifiedSchemas = @() foreach ($schema in $schemas) { $filesThatWereChanged= Invoke-Expression "git diff origin/master --name-only -- $($PSScriptRoot)/../Parsers/$($schema)/Parsers" diff --git a/Parsers/ASimAlert/Parsers/ASimAlert.yaml b/Parsers/ASimAlertEvent/Parsers/ASimAlertEvent.yaml similarity index 97% rename from Parsers/ASimAlert/Parsers/ASimAlert.yaml rename to Parsers/ASimAlertEvent/Parsers/ASimAlertEvent.yaml index 3e9c53d98aa..c2a89f06e56 100644 --- a/Parsers/ASimAlert/Parsers/ASimAlert.yaml +++ b/Parsers/ASimAlertEvent/Parsers/ASimAlertEvent.yaml @@ -9,7 +9,7 @@ Normalization: Version: '0.1' References: - Title: ASIM Alert Schema - Link: https://aka.ms/ASimAlertDoc + Link: https://aka.ms/ASimAlertEventDoc - Title: ASIM Link: https://aka.ms/AboutASIM Description: | diff --git a/Parsers/ASimAlert/Parsers/ASimAlertMicrosoftDefenderXDR.yaml b/Parsers/ASimAlertEvent/Parsers/ASimAlertEventMicrosoftDefenderXDR.yaml similarity index 100% rename from Parsers/ASimAlert/Parsers/ASimAlertMicrosoftDefenderXDR.yaml rename to Parsers/ASimAlertEvent/Parsers/ASimAlertEventMicrosoftDefenderXDR.yaml diff --git a/Parsers/ASimAlert/Parsers/ASimAlertSentinelOneSingularity.yaml b/Parsers/ASimAlertEvent/Parsers/ASimAlertEventSentinelOneSingularity.yaml similarity index 100% rename from Parsers/ASimAlert/Parsers/ASimAlertSentinelOneSingularity.yaml rename to Parsers/ASimAlertEvent/Parsers/ASimAlertEventSentinelOneSingularity.yaml diff --git a/Parsers/ASimAlert/Parsers/imAlert.yaml b/Parsers/ASimAlertEvent/Parsers/imAlertEvent.yaml similarity index 98% rename from Parsers/ASimAlert/Parsers/imAlert.yaml rename to Parsers/ASimAlertEvent/Parsers/imAlertEvent.yaml index f5cf2f8b11e..37661c6cc2b 100644 --- a/Parsers/ASimAlert/Parsers/imAlert.yaml +++ b/Parsers/ASimAlertEvent/Parsers/imAlertEvent.yaml @@ -9,7 +9,7 @@ Normalization: Version: '0.1' References: - Title: ASIM Alert Schema - Link: https://aka.ms/ASimAlertDoc + Link: https://aka.ms/ASimAlertEventDoc - Title: ASIM Link: https://aka.ms/AboutASIM Description: | diff --git a/Parsers/ASimAlert/Parsers/vimAlertEmpty.yaml b/Parsers/ASimAlertEvent/Parsers/vimAlertEventEmpty.yaml similarity index 100% rename from Parsers/ASimAlert/Parsers/vimAlertEmpty.yaml rename to Parsers/ASimAlertEvent/Parsers/vimAlertEventEmpty.yaml diff --git a/Parsers/ASimAlert/Parsers/vimAlertMicrosoftDefenderXDR.yaml b/Parsers/ASimAlertEvent/Parsers/vimAlertEventMicrosoftDefenderXDR.yaml similarity index 100% rename from Parsers/ASimAlert/Parsers/vimAlertMicrosoftDefenderXDR.yaml rename to Parsers/ASimAlertEvent/Parsers/vimAlertEventMicrosoftDefenderXDR.yaml diff --git a/Parsers/ASimAlert/Parsers/vimAlertSentinelOneSingularity.yaml b/Parsers/ASimAlertEvent/Parsers/vimAlertEventSentinelOneSingularity.yaml similarity index 100% rename from Parsers/ASimAlert/Parsers/vimAlertSentinelOneSingularity.yaml rename to Parsers/ASimAlertEvent/Parsers/vimAlertEventSentinelOneSingularity.yaml