Skip to content

SOCRadar-Solution - #13628

Closed
Radargoger wants to merge 0 commit into
Azure:masterfrom
Radargoger:master
Closed

SOCRadar-Solution#13628
Radargoger wants to merge 0 commit into
Azure:masterfrom
Radargoger:master

Conversation

@Radargoger

Copy link
Copy Markdown
Contributor

Required items, please complete

Change(s):
 - Add SOCRadar Sentinel Solution (2 Playbooks, 1 Workbook, 5 Hunting Queries)

 Reason for Change(s):
 - New solution: SOCRadar XTI Platform integration for Microsoft Sentinel
 - Imports SOCRadar alarms as incidents, syncs closed incidents back

 Version Updated:
 - N/A (new solution, no existing detection to update)

 Testing Completed:
 - Yes, tested in live Sentinel environment with SOCRadar API

 Checked that the validations are passing and have addressed any issues that are present:
 - Yes

@Radargoger
Radargoger requested review from a team as code owners February 13, 2026 09:27
@Radargoger

Copy link
Copy Markdown
Contributor Author

@microsoft-github-policy-service agree company="SOCRadar Cyber Intelligence Inc."

@Radargoger

Radargoger commented Feb 13, 2026 via email

Copy link
Copy Markdown
Contributor Author

@Radargoger

Copy link
Copy Markdown
Contributor Author

@microsoft-github-policy-service agree company="SOCRadar Cyber Intelligence Inc."

@Radargoger

Radargoger commented Feb 13, 2026 via email

Copy link
Copy Markdown
Contributor Author

@v-maheshbh v-maheshbh (v-maheshbh) added the New Solution For new Solutions which are new to Microsoft Sentinel label Feb 13, 2026
@v-maheshbh

v-maheshbh (v-maheshbh) commented Feb 18, 2026

Copy link
Copy Markdown
Contributor

Hi Radargoger

For the new workbook, please update the WorkbookMetadata file and add the correct preview images to the images folder and kindly verify the images located at Solutions/SOCRadar/Workbooks/Images/Preview/.

https://github.com/Azure/Azure-Sentinel/blob/master/Workbooks/WorkbooksMetadata.json

Kindly package the solution with version 3.0.0 using the V3 packaging tool.- https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V3/README.md.

Thanks!

@Radargoger
Radargoger requested a review from a team as a code owner February 19, 2026 06:59
@Radargoger

Copy link
Copy Markdown
Contributor Author

v-maheshbh (@v-maheshbh) Thank you we updated

@Radargoger

Radargoger commented Feb 19, 2026 via email

Copy link
Copy Markdown
Contributor Author

@Radargoger
Radargoger requested a review from a team as a code owner February 20, 2026 06:08
@Radargoger

Copy link
Copy Markdown
Contributor Author

Hi v-maheshbh (@v-maheshbh) We've just updated. Please review.

@Radargoger

Copy link
Copy Markdown
Contributor Author

v-maheshbh (@v-maheshbh) could you please run again? Thanks in advance

@Radargoger

Radargoger commented Feb 25, 2026

Copy link
Copy Markdown
Contributor Author

v-maheshbh (@v-maheshbh) Could you please review our solution ? Thanks in advance

CC : azuresentinelgithub

@v-maheshbh

v-maheshbh (v-maheshbh) commented Feb 25, 2026

Copy link
Copy Markdown
Contributor

Hi Radargoger

Kindly ensure that only solution‑related changes are present in the workbookmetadata file.
Please remove any changes other than those related to SOCRadarDashboard.
and ensure the package folder is included, as the solution does not appear to be properly packaged.

Kindly package the solution with version 3.0.0 and update the same in the release notes, ensure the date format is dd‑mm‑yyyy

Refer to an existing solution for folder structure guidance.

Thanks!

Radargoger added a commit to Radargoger/Azure-Sentinel that referenced this pull request Feb 26, 2026
For the review feedback: We added the V3 Package (mainTemplate.json, createUiDefinition.json, testParameters.json), added SOCRadar entry to Workbooks/WorkbooksMetadata.json, and updated ReleaseNotes.md (3.0.0 Initial release).

We also made improvements based on internal feedbacks. All pipeline validations pass (10/10). These changes have been tested end-to-end with cross-region deployment scenarios.

Best regards,
SOCRadar Integration Team
@Radargoger

Radargoger commented Feb 26, 2026

Copy link
Copy Markdown
Contributor Author

v-maheshbh (@v-maheshbh) Yes we updated according to your feedbacks! Thanks in advance.

@Radargoger

Radargoger commented Feb 27, 2026 via email

Copy link
Copy Markdown
Contributor Author

@v-maheshbh

Copy link
Copy Markdown
Contributor

Hi Radargoger

Kindly resolve the branch conflict so we can proceed.

Thanks!

@Radargoger

Radargoger commented Mar 3, 2026 via email

Copy link
Copy Markdown
Contributor Author

@Radargoger

Copy link
Copy Markdown
Contributor Author

Hi v-maheshbh (@v-maheshbh)

We have resolved the branch conflicts as requested. Please let us know if there is anything else needed to proceed and approve.

Best regards,

Burak GOGER
Senior Product Manager 
Enterprise API & Integration Team Lead

@v-maheshbh

Copy link
Copy Markdown
Contributor

Hi Radargoger
As noted in the previous comments, please ensure that the WorkbookMetadata file contains only solution-related updates and version ZIP file is not present in the package folder. Kindly review the file changes carefully prior to committing.

image

kindly check below solution make necessary changes in data file
https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cloudflare%20CCF/Data/Solution_Cloudflare.json

and After completing all updates, please package the solution using the V3 tool, ensuring the package version is set to 3.0.0.
https://github.com/Azure/Azure-Sentinel/blob/master/Tools/Create-Azure-Sentinel-Solution/V3/README.md

Thanks!!

@Radargoger

Radargoger commented Mar 4, 2026

Copy link
Copy Markdown
Contributor Author

Hi v-maheshbh (@v-maheshbh)

We have made the changes as you've requested. Thank you for feedbacks.

Best regards,

Burak GOGER
Senior Product Manager
Enterprise API & Integration Team Lead

@Radargoger

Radargoger commented Mar 4, 2026 via email

Copy link
Copy Markdown
Contributor Author

@Radargoger

Copy link
Copy Markdown
Contributor Author

Hi v-maheshbh (@v-maheshbh)
Regarding the two CI failures:
Playbook Validations failed before validation started.
 The workflow says "Creating unauthenticated Octokit client" and then "API rate limit exceeded".
 Could you please re-run this check?
ARM-TTK (SOCRadar-Solution) shows "IDs Should Be Derived From ResourceIDs" and "Hardcoded Uri / URIs Should Be Properly Constructed".
 These are already documented in the V3 packaging README as ignorable validation issues.
 No code changes are needed on our side.
Thanks.
Burak

@Radargoger

Radargoger commented Mar 10, 2026 via email

Copy link
Copy Markdown
Contributor Author

@Radargoger

Copy link
Copy Markdown
Contributor Author

Hi v-maheshbh (@v-maheshbh), azuresentinelgithub

I wanted to follow up regarding the recent ARM-TTK test failures on our pull request for the SOCRadar solution.

We have thoroughly reviewed the failed checks, specifically the "IDs Should Be Derived from ResourceIDs" and "DeploymentTemplate Must Not Contain Hardcoded Uri" warnings. Based on the Microsoft Sentinel V3 packaging tool (createSolutionV3.ps1) behavior and documentation, we believe these are expected false positives:

  • IDs Should Be Derived from ResourceIDs: This is triggered by the id and contentProductId fields within the contentTemplates and contentPackages resources. The V3 packaging tool generates these formats intentionally as they are required by the Sentinel Content Hub. ARM-TTK flags them because it does not fully recognize these specific Sentinel resource structures.
  • Hardcoded URIs: These point to the management.azure.com endpoints inside our Playbook (Logic App) actions. These are native and necessary for the logic apps to make Azure Management API calls properly.

We intentionally avoided implementing manual workarounds (such as renaming variables, artificially splitting URIs with concat, or removing ID fields) just to bypass the TTK. Modifying the template in that way introduces a significant risk of breaking the actual deployment engine for the Content Hub. The mainTemplate.json remains exactly as generated by the official V3 packaging tool to ensure deployment integrity.

Could you please review and acknowledge these known TTK warnings so we can proceed with the merge process?

Thank you for your time and support!

Best regards,

Burak Goger
Enterprise API & Integration Team Lead

@v-maheshbh

v-maheshbh (v-maheshbh) commented Mar 18, 2026

Copy link
Copy Markdown
Contributor

Hi Radargoger

Kindly resolve the branch conflict.

Thanks!

@Radargoger

Radargoger commented Mar 19, 2026 via email

Copy link
Copy Markdown
Contributor Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

New Solution For new Solutions which are new to Microsoft Sentinel

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants