Sync s1-secops-skills: plugin 1.3.10, MCP 1.3.10, image 1.4.9 (metering exclusion, dashboard tool fixes, doc references) - #107
Merged
nate-smalls-s1 merged 2 commits intoOct 2, 2026
Conversation
…ng exclusion by default, dashboard tool fixes, doc references
… layout (supersedes Sentinel-One#100)
nate-smalls-s1
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Sync s1-secops-skills: plugin 1.3.10, MCP 1.3.10, image 1.4.9
This PR fixes the issues raised in a field smoke test on 2026-10-02. Each one was reproduced and checked on a live console on 2026-10-03. The image
sentinelone/secops-mcps:1.4.9is published for amd64 and arm64.What changed
tag='logVolume') under the source's owndataSource.name. Unfiltered per-source counts included them, and so did schema samples and "is this source silent?" checks.powerquery_run,powerquery_enumerate_sources,pq.run_pq()and schema discovery now drop them. SetincludeMeteringto keep them.tag != 'logVolume'in 42 queries, plus the ingest-health and UEBA workflows.powerquery_schema_discoverno longer reports metering fields (metric,path1,tag,value) as a source's schema.sdl_create_dashboardnow catches a tab labellednameinstead oftabNamebefore sending, and names the right key. The 60-column grid is documented.sdl_save_dashboard_layoutonly saves panel positions. Tested live:The tool now refuses a payload with a different panel count, and warns when content changes would be dropped.
tools/check_skill_refs.pyreports 0 for this tree and for the built.plugin.mgmt-console-api/tests/README.mddocuments now ship with the plugin.skills/sdl-api/references/hec-backdated-ingest.md.count(field != null);count(field=*)returns 400.Upgrading
Change the tag in all three MCP entries from
1.4.8to1.4.9.1.4.8stays published, so you can roll back to it.Checks
hyperautomation/SKILL.mdin either layout, so this PR supersedes fix: correct SKILL.md path in s1-secops-mcp contract tests #100.check_skill_refs.py: 0 unresolved references.