Skip to content

fix: add missing dataSource fields to 36 community parsers - #101

Merged
nate-smalls-s1 merged 1 commit into
Sentinel-One:mainfrom
mickbrowns1:fix/parser-datasource-fields
Oct 2, 2026
Merged

nate-smalls-s1 merged 1 commit into
Sentinel-One:mainfrom
mickbrowns1:fix/parser-datasource-fields

Conversation

@mickbrowns1

Copy link
Copy Markdown
Contributor

Summary

Adds dataSource.name, dataSource.category, and dataSource.vendor to 36 community parsers that were missing one or more of these fields — required for correct loading in the SDL XDR view.

  • dataSource.category set to "security" on all affected parsers
  • 3 parser names aligned to match existing detection queries to avoid breaking detection firing:
    • azure.conf → "Azure Event Hub"
    • zscaler.conf → "Zscaler Internet Access"
    • zscaler_zia.conf → "Zscaler Internet Access"
  • fortigate.conf vendor already matched detection (Fortinet) — confirmed no change needed
  • 2 placeholder-only parsers skipped (singularityidentity, manageengine_adauditplus)
  • 12 vendor-ambiguous parsers deferred pending review (tracked separately)

Test plan

  • Verify parsers load correctly into SDL XDR view under the security category
  • Confirm AzureAD-Entra-alerts, fortinet_fortigate_firewall, and zscaler_http_access detections still fire after parser update

🤖 Generated with Claude Code

Adds dataSource.name, dataSource.category, and dataSource.vendor to all
parsers that were missing them, required for correct SDL XDR view loading.

- dataSource.category set to "security" across all parsers
- 3 values aligned to match existing detection queries:
    azure.conf        → dataSource.name = "Azure Event Hub"
    zscaler.conf      → dataSource.name = "Zscaler Internet Access"
    zscaler_zia.conf  → dataSource.name = "Zscaler Internet Access"
- fortigate.conf vendor already matched detection (Fortinet) — confirmed
- 2 placeholder-only parsers skipped (singularityidentity, manageengine)
- 12 vendor-ambiguous parsers deferred pending review

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@nate-smalls-s1
nate-smalls-s1 merged commit 1a3450f into Sentinel-One:main Oct 2, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants