[M365_Defender] Enhancement - Add support for IdentityInfo Table - #12214
Conversation
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
|
/test |
2 similar comments
|
/test |
|
/test |
|
/test |
|
@jvalente-salemstate, can you run |
We should be good. I was missing a few descriptions in |
|
/test |
🚀 Benchmarks reportTo see the full report comment with |
|
@jvalente-salemstate, it looks good as of now, but can we add some more tests so we can have the test coverage up for SonarQube? |
I could try, but I can't access SonarQube to see which tests or the results. Is it the null fields in the two samples I added? I can (even if that isn't the issue) add another sample with a few more populated since I found a couple that did have more info. |
|
/test |
|
💚 Build Succeeded
History
|
It seems to be failing mainly on As per elastic/elastic-package#1915 (comment), the fields files are checked when CI system tests are run for the package. But we don't have system tests for this |
|
Package m365_defender - 2.19.0 containing this change is available at https://epr.elastic.co/package/m365_defender/2.19.0/ |



Proposed commit message
Microsoft now forwards
AdvancedHunting-IdentityInfovia the XDR streaming API. This adds support for this table and its fields.Fields were checked against MS docs, which is not current. Additional fields from sample events were included.
Checklist
changelog.ymlfile.Related issues