Skip to content

Sync s1-secops-skills: plugin 1.3.10, MCP 1.3.10, image 1.4.9 (metering exclusion, dashboard tool fixes, doc references) - #107

Merged
nate-smalls-s1 merged 2 commits into
Sentinel-One:mainfrom
pmoses-s1:fix/skills-1.3.10-metering-exclusion
Oct 2, 2026
Merged

nate-smalls-s1 merged 2 commits into
Sentinel-One:mainfrom
pmoses-s1:fix/skills-1.3.10-metering-exclusion

Conversation

@pmoses-s1

@pmoses-s1 pmoses-s1 commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Sync s1-secops-skills: plugin 1.3.10, MCP 1.3.10, image 1.4.9

This PR fixes the issues raised in a field smoke test on 2026-10-02. Each one was reproduced and checked on a live console on 2026-10-03. The image sentinelone/secops-mcps:1.4.9 is published for amd64 and arm64.

What changed

  • Ingest-metering rows are excluded by default. Every ingest writes receive-time accounting rows (tag='logVolume') under the source's own dataSource.name. Unfiltered per-source counts included them, and so did schema samples and "is this source silent?" checks.
    • powerquery_run, powerquery_enumerate_sources, pq.run_pq() and schema discovery now drop them. Set includeMetering to keep them.
    • The sdl-solutions templates now include tag != 'logVolume' in 42 queries, plus the ingest-health and UEBA workflows.
    • Measured over a fixed 12h window: 383,044 rows unfiltered, of which 7,390 were metering. The ingest-health "events missing category" panel had flagged 14 of 14 sources, all because of metering rows. It now flags 0.
  • powerquery_schema_discover no longer reports metering fields (metric, path1, tag, value) as a source's schema.
  • sdl_create_dashboard now catches a tab labelled name instead of tabName before sending, and names the right key. The 60-column grid is documented.
  • sdl_save_dashboard_layout only saves panel positions. Tested live:
    • Content changes in the payload are ignored.
    • A shorter payload changes nothing.
    • A longer payload is refused.
      The tool now refuses a payload with a different panel count, and warns when content changes would be dropped.
  • Doc references. 36 pointers that didn't resolve inside the installed plugin are fixed or marked as source-repo only. The new tools/check_skill_refs.py reports 0 for this tree and for the built .plugin.
  • The five lifecycle tests that mgmt-console-api/tests/README.md documents now ship with the plugin.
  • HEC "shadow copies". The receive-time rows are ingest metering, not duplicated events. The note is replaced by skills/sdl-api/references/hec-backdated-ingest.md.
  • powerquery pitfalls. To count how many events carry a field, use count(field != null); count(field=*) returns 400.

Upgrading

Change the tag in all three MCP entries from 1.4.8 to 1.4.9. 1.4.8 stays published, so you can roll back to it.

Checks

@nate-smalls-s1
nate-smalls-s1 merged commit 38b513c into Sentinel-One:main Oct 2, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants