Skip to content

Databricks SQL Addition AWS Queries - #2130

Merged
zaynahsmith-dasilva merged 2 commits into
developfrom
databricks-queries-aws
Jul 7, 2026
Merged

zaynahsmith-dasilva merged 2 commits into
developfrom
databricks-queries-aws

Conversation

@zaynahsmith-dasilva

Copy link
Copy Markdown
Contributor

Background

Changes

  • Added a databricks sql YAML key to the existing SQL queries within the AWS log type.

Testing

@zaynahsmith-dasilva
zaynahsmith-dasilva requested review from a team as code owners July 6, 2026 17:23
@zaynahsmith-dasilva zaynahsmith-dasilva added the tuning detection tuning label Jul 6, 2026
@cursor

cursor Bot commented Jul 6, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Low risk because the changes are limited to disabled scheduled query YAML definitions and mostly add engine-specific SQL translations. Review should focus on Databricks SQL syntax parity with the existing Snowflake logic.

Overview
Adds DatabricksQuery definitions to a set of AWS scheduled queries and renames the existing Query fields to SnowflakeQuery.

The Databricks versions translate Snowflake-specific JSON access, array aggregation, QUALIFY, and timestamp syntax for detections covering CloudTrail, VPC Flow/DNS, S3 download, SSM session, and CrowdStrike unmanaged-device scenarios.

Reviewed by Cursor Bugbot for commit 77a6308. Bugbot is set up for automated code reviews on this repo. Configure here.

@zaynahsmith-dasilva
zaynahsmith-dasilva added this pull request to the merge queue Jul 7, 2026
Merged via the queue into develop with commit 960c912 Jul 7, 2026
19 checks passed
@zaynahsmith-dasilva
zaynahsmith-dasilva deleted the databricks-queries-aws branch July 7, 2026 16:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tuning detection tuning

2 participants