Update Cisco ETD connector to use the new Message Event Logs - #14005
Update Cisco ETD connector to use the new Message Event Logs #14005sepinto2020 wants to merge 3 commits into
Conversation
|
@microsoft-github-policy-service agree company="Cisco"
…On Tue, Apr 7, 2026 at 11:52 AM microsoft-github-policy-service[bot] < ***@***.***> wrote:
*microsoft-github-policy-service[bot]* left a comment
(Azure/Azure-Sentinel#14005)
<#14005 (comment)>
@sepinto2020 <https://github.com/sepinto2020> please read the following
Contributor License Agreement(CLA). If you agree with the CLA, please reply
with the following information.
@microsoft-github-policy-service agree [company="{your company}"]
Options:
- (default - no company specified) I have sole ownership of
intellectual property rights to my Submissions and I am not making
Submissions in the course of work for my employer.
@microsoft-github-policy-service agree
- (when company given) I am making Submissions in the course of work
for my employer (or my employer has intellectual property rights in my
Submissions by contract or applicable law). I have permission from my
employer to make Submissions and enter into this Agreement on behalf of my
employer. By signing below, the defined term “You” includes me and my
employer.
@microsoft-github-policy-service agree company="Microsoft"
Contributor License Agreement Contribution License Agreement
This Contribution License Agreement (*“Agreement”*) is agreed to by the
party signing below (*“You”*),
and conveys certain license rights to Microsoft Corporation and its
affiliates (“Microsoft”) for Your
contributions to Microsoft open source projects. This Agreement is
effective as of the latest signature
date below.
1. *Definitions*.
*“Code”* means the computer software code, whether in human-readable
or machine-executable form,
that is delivered by You to Microsoft under this Agreement.
*“Project”* means any of the projects owned or managed by Microsoft
and offered under a license
approved by the Open Source Initiative (www.opensource.org).
*“Submit”* is the act of uploading, submitting, transmitting, or
distributing code or other content to any
Project, including but not limited to communication on electronic
mailing lists, source code control
systems, and issue tracking systems that are managed by, or on behalf
of, the Project for the purpose of
discussing and improving that Project, but excluding communication
that is conspicuously marked or
otherwise designated in writing by You as “Not a Submission.”
*“Submission”* means the Code and any other copyrightable material
Submitted by You, including any
associated comments and documentation.
2. *Your Submission*. You must agree to the terms of this Agreement
before making a Submission to any
Project. This Agreement covers any and all Submissions that You, now
or in the future (except as
described in Section 4 below), Submit to any Project.
3. *Originality of Work*. You represent that each of Your Submissions
is entirely Your original work.
Should You wish to Submit materials that are not Your original work,
You may Submit them separately
to the Project if You (a) retain all copyright and license information
that was in the materials as You
received them, (b) in the description accompanying Your Submission,
include the phrase “Submission
containing materials of a third party:” followed by the names of the
third party and any licenses or other
restrictions of which You are aware, and (c) follow any other
instructions in the Project’s written
guidelines concerning Submissions.
4. *Your Employer*. References to “employer” in this Agreement include
Your employer or anyone else
for whom You are acting in making Your Submission, e.g. as a
contractor, vendor, or agent. If Your
Submission is made in the course of Your work for an employer or Your
employer has intellectual
property rights in Your Submission by contract or applicable law, You
must secure permission from Your
employer to make the Submission before signing this Agreement. In that
case, the term “You” in this
Agreement will refer to You and the employer collectively. If You
change employers in the future and
desire to Submit additional Submissions for the new employer, then You
agree to sign a new Agreement
and secure permission from the new employer before Submitting those
Submissions.
5. *Licenses*.
- *Copyright License*. You grant Microsoft, and those who receive the
Submission directly or
indirectly from Microsoft, a perpetual, worldwide, non-exclusive,
royalty-free, irrevocable license in the
Submission to reproduce, prepare derivative works of, publicly
display, publicly perform, and distribute
the Submission and such derivative works, and to sublicense any or all
of the foregoing rights to third
parties.
- *Patent License*. You grant Microsoft, and those who receive the
Submission directly or
indirectly from Microsoft, a perpetual, worldwide, non-exclusive,
royalty-free, irrevocable license under
Your patent claims that are necessarily infringed by the Submission or
the combination of the
Submission with the Project to which it was Submitted to make, have
made, use, offer to sell, sell and
import or otherwise dispose of the Submission alone or with the
Project.
- *Other Rights Reserved*. Each party reserves all rights not
expressly granted in this Agreement.
No additional licenses or rights whatsoever (including, without
limitation, any implied licenses) are
granted by implication, exhaustion, estoppel or otherwise.
6. *Representations and Warranties*. You represent that You are
legally entitled to grant the above
licenses. You represent that each of Your Submissions is entirely Your
original work (except as You may
have disclosed under Section 3). You represent that You have secured
permission from Your employer to
make the Submission in cases where Your Submission is made in the
course of Your work for Your
employer or Your employer has intellectual property rights in Your
Submission by contract or applicable
law. If You are signing this Agreement on behalf of Your employer, You
represent and warrant that You
have the necessary authority to bind the listed employer to the
obligations contained in this Agreement.
You are not expected to provide support for Your Submission, unless
You choose to do so. UNLESS
REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING, AND EXCEPT FOR THE
WARRANTIES
EXPRESSLY STATED IN SECTIONS 3, 4, AND 6, THE SUBMISSION PROVIDED
UNDER THIS AGREEMENT IS
PROVIDED WITHOUT WARRANTY OF ANY KIND, INCLUDING, BUT NOT LIMITED TO,
ANY WARRANTY OF
NONINFRINGEMENT, MERCHANTABILITY, OR FITNESS FOR A PARTICULAR PURPOSE.
7. *Notice to Microsoft*. You agree to notify Microsoft in writing of
any facts or circumstances of which
You later become aware that would make Your representations in this
Agreement inaccurate in any
respect.
8. *Information about Submissions*. You agree that contributions to
Projects and information about
contributions may be maintained indefinitely and disclosed publicly,
including Your name and other
information that You submit with Your Submission.
9. *Governing Law/Jurisdiction*. This Agreement is governed by the
laws of the State of Washington, and
the parties consent to exclusive jurisdiction and venue in the federal
courts sitting in King County,
Washington, unless no federal subject matter jurisdiction exists, in
which case the parties consent to
exclusive jurisdiction and venue in the Superior Court of King County,
Washington. The parties waive all
defenses of lack of personal jurisdiction and forum non-conveniens.
10. *Entire Agreement/Assignment*. This Agreement is the entire
agreement between the parties, and
supersedes any and all prior agreements, understandings or
communications, written or oral, between
the parties relating to the subject matter hereof. This Agreement may
be assigned by Microsoft.
—
Reply to this email directly, view it on GitHub
<#14005 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ARDGTVTCBEWXWPZLIT72LUL4UTMVNAVCNFSM6AAAAACXPJGIK6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHM2DCOJYGQZTKMZXG4>
.
You are receiving this because you were mentioned.Message ID:
***@***.***>
--
Sérgio Pinto
|
There was a problem hiding this comment.
Pull request overview
Note
Copilot was unable to run its full agentic suite in this review.
Updates the Cisco ETD Microsoft Sentinel solution to align with the new Message Event Logs REST API–based ingestion and refreshes solution artifacts accordingly.
Changes:
- Replaced the legacy workbook with a new Messages-focused workbook built around the
messagedynamic payload. - Updated solution metadata/data and release notes to reflect the new content and versioning.
- Transitioned solution packaging artifacts away from the legacy Function App connector toward a CCP/RestApiPoller-based approach (packaging files not reviewed here per repo policy).
Reviewed changes
Copilot reviewed 18 out of 24 changed files in this pull request and generated 7 comments.
Show a summary per file
| File | Description |
|---|---|
| Solutions/Cisco ETD/Workbooks/CiscoETDMessages.json | Adds a new workbook targeting message event logs and richer message fields. |
| Solutions/Cisco ETD/Workbooks/CiscoETD.json | Removes the legacy workbook that relied on old table fields. |
| Solutions/Cisco ETD/SolutionMetadata.json | Updates marketplace metadata (offerId, publish date, categories, support). |
| Solutions/Cisco ETD/ReleaseNotes.md | Adds a new release entry for the message event logs update. |
| Solutions/Cisco ETD/Package/testParameters.json | Updates ARM test parameters (not reviewed; ignored path). |
| Solutions/Cisco ETD/Package/mainTemplate.json | Updates packaging template for new connector approach (not reviewed; ignored path). |
| Solutions/Cisco ETD/Package/createUiDefinition.json | Updates installer UI text/links (not reviewed; ignored path). |
| Solutions/Cisco ETD/Data/Solution_CiscoETD.json | Updates solution manifest (workbook reference, connector reference, version/meta fields). |
| Solutions/Cisco ETD/Data Connectors/requirements.txt | Removes Function App requirements (not reviewed; ignored path). |
| Solutions/Cisco ETD/Data Connectors/azuredeploy_CiscoETD_API_FunctionApp.json | Removes legacy Function App deployment template (not reviewed; ignored path). |
| Solutions/Cisco ETD/Data Connectors/CiscoETD_ccp/CiscoETD_connectorDefinition.json | Adds connector definition (not reviewed; ignored path). |
| Solutions/Cisco ETD/Data Connectors/CiscoETD_ccp/CiscoETD_Table.json | Adds table schema definition (not reviewed; ignored path). |
| Solutions/Cisco ETD/Data Connectors/CiscoETD_ccp/CiscoETD_PollerConfig.json | Adds poller configuration (not reviewed; ignored path). |
| Solutions/Cisco ETD/Data Connectors/CiscoETD_ccp/CiscoETD_DCR.json | Adds DCR definition (not reviewed; ignored path). |
| Solutions/Cisco ETD/Data Connectors/CiscoETD_API_FunctionApp.json | Removes legacy connector definition (not reviewed; ignored path). |
| Solutions/Cisco ETD/Data Connectors/CiscoETDAzureSentinelConnector/* | Removes legacy Azure Function implementation (not reviewed; ignored path). |
| "type": 1, | ||
| "content": { | ||
| "json": "## Cisco Email Threat Defense\nThis workbook uses the **CiscoETDMessages** parser to visualize email threat data from the Cisco ETD connector. Data is sourced from the `message` dynamic column — all fields are parsed at query time. Use the time range filter above to scope all tiles.\n\n> **Note:** Verdict analysis excludes `update` events (re-remediation records that carry no sender/verdict data)." | ||
| }, | ||
| "name": "header-text" | ||
| }, |
There was a problem hiding this comment.
The workbook assumes a CiscoETDMessages parser/function exists (and that it projects columns like Verdict, Sender, Recipient, etc.). In the updated solution manifest, Parsers is empty, so unless this parser is created elsewhere during deployment, all workbook queries will fail with “failed to resolve table or column expression”. Either (mandatory) include the parser KQL function in Solutions/Cisco ETD/Parsers/ and reference it in Data/Solution_CiscoETD.json, or (alternative) rewrite the workbook queries to use CiscoETD_CL directly and parse message inline within each query.
| "version": "KqlItem/1.0", | ||
| "query": "CiscoETDMessages\n| extend EventType = tostring(message['eventType'])\n| extend Folder = tostring(message['action']['folder'])\n| summarize\n ['Total Events'] = count(),\n ['New Messages'] = countif(EventType =~ 'create'),\n ['Remediation Updates']= countif(EventType =~ 'update'),\n Phishing = countif(Verdict =~ 'phishing'),\n Malicious = countif(Verdict =~ 'malicious'),\n BEC = countif(Verdict =~ 'bec'),\n Graymail = countif(Verdict =~ 'graymail'),\n Spam = countif(Verdict =~ 'spam'),\n Scam = countif(Verdict =~ 'scam'),\n Quarantined = countif(Folder =~ 'quarantine'),\n ['Sent to Junk'] = countif(Folder =~ 'junk')", | ||
| "size": 4, |
There was a problem hiding this comment.
The workbook assumes a CiscoETDMessages parser/function exists (and that it projects columns like Verdict, Sender, Recipient, etc.). In the updated solution manifest, Parsers is empty, so unless this parser is created elsewhere during deployment, all workbook queries will fail with “failed to resolve table or column expression”. Either (mandatory) include the parser KQL function in Solutions/Cisco ETD/Parsers/ and reference it in Data/Solution_CiscoETD.json, or (alternative) rewrite the workbook queries to use CiscoETD_CL directly and parse message inline within each query.
| { | ||
| "publisherId": "cisco", | ||
| "offerId": "azure-sentinel-solution-cisco-etd", | ||
| "firstPublishDate": "2026-02-04", |
There was a problem hiding this comment.
firstPublishDate represents the initial publish date of the solution, not the date of this update. This PR changes it from 2024 to 2026, which will misrepresent the solution’s history and can cause downstream catalog/upgrade issues. Revert firstPublishDate to the original first publish date (or the actual first publication date if 2024-03-04 was incorrect).
| "firstPublishDate": "2026-02-04", | |
| "firstPublishDate": "2024-03-04", |
| ], | ||
| "verticals": [] |
There was a problem hiding this comment.
categories.verticals is optional; when not applicable it should be omitted rather than set to an empty array. Dropping the empty verticals improves metadata cleanliness and avoids failing stricter validators that treat empty optional arrays as invalid.
| ], | |
| "verticals": [] | |
| ] |
| | **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** | | ||
| |-------------|--------------------------------|---------------------------------------------| | ||
| | 3.0.0 | 11-02-2024 | Initial Solution Release | No newline at end of file | ||
| | 3.0.0 | 11-02-2024 | Initial Solution Release | | ||
| | 3.0.1 | 06-04-2026 | Update with Messsage Events Logs | No newline at end of file |
There was a problem hiding this comment.
The release notes table does not follow the required conventions: (1) versions must be in descending order (so 3.0.1 should appear above 3.0.0), and (2) fix the spelling in the change description (“Messsage”). Please also ensure the table formatting is consistent (single | delimiters, no extra spacing) to avoid markdown/table validation failures.
| | **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** | | |
| |-------------|--------------------------------|---------------------------------------------| | |
| | 3.0.0 | 11-02-2024 | Initial Solution Release | | |
| \ No newline at end of file | |
| | 3.0.0 | 11-02-2024 | Initial Solution Release | | |
| | 3.0.1 | 06-04-2026 | Update with Messsage Events Logs | | |
| | **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** | | |
| |---|---|---| | |
| | 3.0.1 | 06-04-2026 | Update with Message Events Logs | | |
| | 3.0.0 | 11-02-2024 | Initial Solution Release | |
| "Name": "CiscoETD", | ||
| "Author": "Cisco", | ||
| "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/cisco-logo-transparent.svg\" width=\"75px\" height=\"75px\">", | ||
| "Description": "The Cisco Email Threat Defense (ETD) solution for Microsoft Sentinel enables you to ingest message events and threat data from Cisco ETD into Microsoft Sentinel using the Log Export API with nested polling.", | ||
| "Workbooks": [ | ||
| "Workbooks/CiscoETDMessages.json" | ||
| ], |
There was a problem hiding this comment.
Solution_CiscoETD.json violates the solution-manifest requirements and is likely to fail solution validation/packaging: (mandatory) Author must include contact info in the form {Org} - {email}; (mandatory) Is1PConnector (boolean) is missing; (mandatory) Name should align with folder naming conventions (the folder is Cisco ETD, but Name is CiscoETD), and BasePath points to a different directory (...\\CiscoETDv5) rather than the actual solution folder; (mandatory) Version (1.0.2) does not align with the release notes (3.0.1). Align Name/BasePath/Version, add Is1PConnector, and use the required Author format so the solution can pass repo validators.
| "Data Connectors": [ | ||
| "Data Connectors/CiscoETD_ccp/CiscoETD_connectorDefinition.json" | ||
| ], | ||
| "Watchlists": [], | ||
| "dependentDomainSolutionIds": [], | ||
| "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\CiscoETDv5", | ||
| "Version": "1.0.2", | ||
| "Metadata": "SolutionMetadata.json", | ||
| "TemplateSpec": true, | ||
| "StaticDataConnectorIds": [] |
There was a problem hiding this comment.
Solution_CiscoETD.json violates the solution-manifest requirements and is likely to fail solution validation/packaging: (mandatory) Author must include contact info in the form {Org} - {email}; (mandatory) Is1PConnector (boolean) is missing; (mandatory) Name should align with folder naming conventions (the folder is Cisco ETD, but Name is CiscoETD), and BasePath points to a different directory (...\\CiscoETDv5) rather than the actual solution folder; (mandatory) Version (1.0.2) does not align with the release notes (3.0.1). Align Name/BasePath/Version, add Is1PConnector, and use the required Author format so the solution can pass repo validators.
|
Hi sepinto2020, please check copilot suggestions and update it and commit the changes. Thanks! |
|
working on it.
…On Mon, Apr 20, 2026 at 1:38 PM v-shukore ***@***.***> wrote:
*v-shukore* left a comment (Azure/Azure-Sentinel#14005)
<#14005?email_source=notifications&email_token=ARDGTVSMLIMWCDXZKGKGSRT4WYK5NA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTIMRYGA3TQNRSGE42M4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJNLQOJPWG33NNVSW45C7N5YGK3S7MNWGSY3L#issuecomment-4280786219>
Hi @sepinto2020 <https://github.com/sepinto2020>, please check copilot
suggestions and update it and commit the changes. Thanks!
—
Reply to this email directly, view it on GitHub
<#14005?email_source=notifications&email_token=ARDGTVSMLIMWCDXZKGKGSRT4WYK5NA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTIMRYGA3TQNRSGE42M4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJNLQOJPWG33NNVSW45C7N5YGK3S7MNWGSY3L#issuecomment-4280786219>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ARDGTVUHHKJMXUTD4KBWJXL4WYK5NAVCNFSM6AAAAACXPJGIK6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHM2DEOBQG44DMMRRHE>
.
You are receiving this because you were mentioned.Message ID:
***@***.***>
--
Sérgio Pinto
|
|
I uploaded a new commit for review.
There is an issue with the workbook that does not show up as a template
inside Defender. This is what I see when I compile the connector:
Downloading
/Users/sepinto/MS_Sentinel_Connector/Azure-Sentinel/Solutions/Cisco
ETD/Workbooks/CiscoETDMessages.json
Generating Workbook using Workbooks/CiscoETDMessages.json
Downloading
/Users/sepinto/MS_Sentinel_Connector/Azure-Sentinel/Workbooks/WorkbooksMetadata.json
TemplateSpec Workbook Metadata Dependencies errors occurred: Conversion
from JSON failed with error: After parsing a value an unexpected character
was encountered: ". Path '[436].provider', line 10391, position 4.
On Tue, Apr 21, 2026 at 7:36 AM Sergio Pinto ***@***.***>
wrote:
… working on it.
On Mon, Apr 20, 2026 at 1:38 PM v-shukore ***@***.***>
wrote:
> *v-shukore* left a comment (Azure/Azure-Sentinel#14005)
> <#14005?email_source=notifications&email_token=ARDGTVSMLIMWCDXZKGKGSRT4WYK5NA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTIMRYGA3TQNRSGE42M4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJNLQOJPWG33NNVSW45C7N5YGK3S7MNWGSY3L#issuecomment-4280786219>
>
> Hi @sepinto2020 <https://github.com/sepinto2020>, please check copilot
> suggestions and update it and commit the changes. Thanks!
>
> —
> Reply to this email directly, view it on GitHub
> <#14005?email_source=notifications&email_token=ARDGTVSMLIMWCDXZKGKGSRT4WYK5NA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTIMRYGA3TQNRSGE42M4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJNLQOJPWG33NNVSW45C7N5YGK3S7MNWGSY3L#issuecomment-4280786219>,
> or unsubscribe
> <https://github.com/notifications/unsubscribe-auth/ARDGTVUHHKJMXUTD4KBWJXL4WYK5NAVCNFSM6AAAAACXPJGIK6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHM2DEOBQG44DMMRRHE>
> .
> You are receiving this because you were mentioned.Message ID:
> ***@***.***>
>
--
Sérgio Pinto
--
Sérgio Pinto
|
sepinto2020
left a comment
There was a problem hiding this comment.
Fixed error. Asking for a review
|
Hi sepinto2020, don't modify existing zip 3.0.0 uncommit that change and keep only latest zip which created with version 3.0.1. |
c61baf4 to
94a05b8
Compare
|
New commit to fix the previous PR errors. |
|
Hi sepinto2020, please resolve branch conflicts. Thanks! |
|
Hi sepinto2020, do not to delete 3.0.0 zip package. Instead, uncommit that change and remove it from this PR, keeping only the newly created zip package. If the old package is deleted, it could affect other customers since that package is currently live. |
|
Closing the PR as per MS suggestion. Will open a new one. |


Change(s):
Reason for Change(s):
Version updated:
Testing Completed:
Checked that the validations are passing and have addressed any issues that are present: