Skip to content

m365_defender: improve user.name field handling - #13554

Merged
efd6 merged 1 commit into
elastic:mainfrom
efd6:13514-m365_defender
Apr 30, 2025
Merged

m365_defender: improve user.name field handling#13554
efd6 merged 1 commit into
elastic:mainfrom
efd6:13514-m365_defender

Conversation

@efd6

@efd6 efd6 commented Apr 16, 2025

Copy link
Copy Markdown
Contributor

Proposed commit message

m365_defender: improve user.name field handling

The fields that contain the user name vary, so successively look in
known places until the value is found.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Screenshots

@efd6 efd6 added enhancement New feature or request Integration:m365_defender Microsoft Defender XDR Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Apr 16, 2025
@efd6 efd6 self-assigned this Apr 16, 2025
The fields that contain the user name vary, so successively look in
known places until the value is found.
@efd6
efd6 force-pushed the 13514-m365_defender branch from a7ef269 to 248e2de Compare April 16, 2025 02:49
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

cc @efd6

@efd6
efd6 marked this pull request as ready for review April 16, 2025 03:13
@efd6
efd6 requested a review from a team as a code owner April 16, 2025 03:13
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@efd6
efd6 merged commit e8220b4 into elastic:main Apr 30, 2025
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package m365_defender - 3.3.0 containing this change is available at https://epr.elastic.co/package/m365_defender/3.3.0/

seanrathier pushed a commit to seanrathier/integrations that referenced this pull request May 1, 2025
The fields that contain the user name vary, so successively look in
known places until the value is found.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:m365_defender Microsoft Defender XDR Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants