diff --git a/Parsers/ASimAuthentication/ARM/vimAuthenticationEmpty/vimAuthenticationEmpty.json b/Parsers/ASimAuthentication/ARM/vimAuthenticationEmpty/vimAuthenticationEmpty.json index d3929954085..44ac85d48a0 100644 --- a/Parsers/ASimAuthentication/ARM/vimAuthenticationEmpty/vimAuthenticationEmpty.json +++ b/Parsers/ASimAuthentication/ARM/vimAuthenticationEmpty/vimAuthenticationEmpty.json @@ -27,7 +27,7 @@ "displayName": "Authentication ASIM schema function", "category": "ASIM", "FunctionAlias": "vimAuthenticationEmpty", - "query": "let EmptyAuthenticationTable=datatable(\n TimeGenerated:datetime,\n Type:string,\n ActingAppId:string,\n ActingAppName:string,\n ActingAppType:string,\n ActingOriginalAppType:string,\n ActorDNUsername:string,\n ActorOriginalUserType:string,\n ActorScope:string,\n ActorScopeId:string,\n ActorSessionId:string,\n ActorSimpleUsername:string,\n ActorUserAadId:string,\n ActorUserAWSId:string,\n ActorUserId:string,\n ActorUserIdType:string,\n ActorUsername:string,\n ActorUsernameType:string,\n ActorUserOktaId:string,\n ActorUserPuid:string,\n ActorUserSid:string,\n ActorUserType:string,\n ActorUserUid:string,\n ActorUserUpn:string,\n ActorWindowsUsername:string,\n AdditionalFields:dynamic,\n Application:string,\n Dst:string,\n Dvc:string,\n DvcAction:string,\n DvcDescription:string,\n DvcDomain:string,\n DvcDomainType:string,\n DvcFQDN:string,\n DvcHostname:string,\n DvcId:string,\n DvcIdType:string,\n DvcInterface:string,\n DvcIpAddr:string,\n DvcMacAddr:string,\n DvcOriginalAction:string,\n DvcOs:string,\n DvcOsVersion:string,\n DvcScope:string,\n DvcScopeId:string,\n DvcZone:string,\n EventCount:int,\n EventEndTime:datetime,\n EventMessage:string,\n EventOriginalResultDetails:string,\n EventOriginalSeverity:string,\n EventOriginalSubType:string,\n EventOriginalType:string,\n EventOriginalUid:string,\n EventOwner:string,\n EventProduct:string,\n EventProductVersion:string,\n EventReportUrl:string,\n EventResult:string,\n EventResultDetails:string,\n EventSchema:string,\n EventSchemaVersion:string,\n EventSeverity:string,\n EventStartTime:datetime,\n EventSubType:string,\n EventType:string,\n EventUid:string,\n EventVendor:string,\n HttpUserAgent:string,\n IpAddr:string,\n LogonMethod:string,\n LogonProtocol:string,\n LogonTarget:string,\n Rule:string,\n RuleName:string,\n RuleNumber:int,\n Src:string,\n SrcDescription:string,\n SrcDeviceType:string,\n SrcDomain:string,\n SrcDomainType:string,\n SrcDvcHostnameType:string,\n SrcDvcId:string,\n SrcDvcIdType:string,\n SrcDvcOs:string,\n SrcDvcScope:string,\n SrcDvcScopeId:string,\n SrcFQDN:string,\n SrcGeoCity:string,\n SrcGeoCountry:string,\n SrcGeoLatitude:real,\n SrcGeoLongitude:real,\n SrcGeoRegion:string,\n SrcHostname:string,\n SrcIpAddr:string,\n SrcIsp:string,\n SrcOriginalRiskLevel:string,\n SrcPortNumber:string,\n SrcRiskLevel:int,\n TargetAppId:string,\n TargetAppName:string,\n TargetAppType:string,\n TargetDescription:string,\n TargetDeviceType:string,\n TargetDNUsername:string,\n TargetDomain:string,\n TargetDomainType:string,\n TargetDvcId:string,\n TargetDvcIdType:string,\n TargetDvcOs:string,\n TargetDvcScope:string,\n TargetDvcScopeId:string,\n TargetFQDN:string,\n TargetGeoCity:string,\n TargetGeoCountry:string,\n TargetGeoLatitude:real,\n TargetGeoLongitude:real,\n TargetGeoRegion:string,\n TargetHostname:string,\n TargetIpAddr:string,\n TargetOriginalAppType:string,\n TargetOriginalRiskLevel:string,\n TargetOriginalUserType:string,\n TargetPortNumber:int,\n TargetRiskLevel:int,\n TargetSessionId:string,\n TargetSimpleUsername:string,\n TargetUrl:string,\n TargetUserAadId:string,\n TargetUserAWSId:string,\n TargetUserId:string,\n TargetUserIdType:string,\n TargetUsername:string,\n TargetUsernameType:string,\n TargetUserOktaId:string,\n TargetUserPuid:string,\n TargetUserScope:string,\n TargetUserScopeId:string,\n TargetUserSid:string,\n TargetUserType:string,\n TargetUserUid:string,\n TargetUserUpn:string,\n TargetWindowsUsername:string,\n ThreatCategory:string,\n ThreatConfidence:int,\n ThreatField:string,\n ThreatFirstReportedTime:datetime,\n ThreatId:string,\n ThreatIpAddr:string,\n ThreatIsActive:bool,\n ThreatLastReportedTime:datetime,\n ThreatName:string,\n ThreatOriginalConfidence:string,\n ThreatOriginalRiskLevel:string,\n ThreatRiskLevel:int,\n User:string\n)[];\nEmptyAuthenticationTable", + "query": "let EmptyAuthenticationTable=datatable(\n TimeGenerated:datetime,\n Type:string,\n ActingAppId:string,\n ActingAppName:string,\n ActingAppType:string,\n ActingOriginalAppType:string,\n ActorDNUsername:string,\n ActorOriginalUserType:string,\n ActorScope:string,\n ActorScopeId:string,\n ActorSessionId:string,\n ActorSimpleUsername:string,\n ActorUserAadId:string,\n ActorUserAWSId:string,\n ActorUserId:string,\n ActorUserIdType:string,\n ActorUsername:string,\n ActorUsernameType:string,\n ActorUserOktaId:string,\n ActorUserPuid:string,\n ActorUserSid:string,\n ActorUserType:string,\n ActorUserUid:string,\n ActorUserUpn:string,\n ActorWindowsUsername:string,\n AdditionalFields:dynamic,\n Application:string,\n Dst:string,\n Dvc:string,\n DvcAction:string,\n DvcDescription:string,\n DvcDomain:string,\n DvcDomainType:string,\n DvcFQDN:string,\n DvcHostname:string,\n DvcId:string,\n DvcIdType:string,\n DvcInterface:string,\n DvcIpAddr:string,\n DvcMacAddr:string,\n DvcOriginalAction:string,\n DvcOs:string,\n DvcOsVersion:string,\n DvcScope:string,\n DvcScopeId:string,\n DvcZone:string,\n EventCount:int,\n EventEndTime:datetime,\n EventMessage:string,\n EventOriginalResultDetails:string,\n EventOriginalSeverity:string,\n EventOriginalSubType:string,\n EventOriginalType:string,\n EventOriginalUid:string,\n EventOwner:string,\n EventProduct:string,\n EventProductVersion:string,\n EventReportUrl:string,\n EventResult:string,\n EventResultDetails:string,\n EventSchema:string,\n EventSchemaVersion:string,\n EventSeverity:string,\n EventStartTime:datetime,\n EventSubType:string,\n EventType:string,\n EventUid:string,\n EventVendor:string,\n HttpUserAgent:string,\n IpAddr:string,\n LogonMethod:string,\n LogonProtocol:string,\n LogonTarget:string,\n Rule:string,\n RuleName:string,\n RuleNumber:int,\n Src:string,\n SrcDescription:string,\n SrcDeviceType:string,\n SrcDomain:string,\n SrcDomainType:string,\n SrcDvcHostnameType:string,\n SrcDvcId:string,\n SrcDvcIdType:string,\n SrcDvcOs:string,\n SrcDvcScope:string,\n SrcDvcScopeId:string,\n SrcFQDN:string,\n SrcGeoCity:string,\n SrcGeoCountry:string,\n SrcGeoLatitude:real,\n SrcGeoLongitude:real,\n SrcGeoRegion:string,\n SrcHostname:string,\n SrcIpAddr:string,\n SrcIsp:string,\n SrcOriginalRiskLevel:string,\n SrcPortNumber:int,\n SrcRiskLevel:int,\n TargetAppId:string,\n TargetAppName:string,\n TargetAppType:string,\n TargetDescription:string,\n TargetDeviceType:string,\n TargetDNUsername:string,\n TargetDomain:string,\n TargetDomainType:string,\n TargetDvcId:string,\n TargetDvcIdType:string,\n TargetDvcOs:string,\n TargetDvcScope:string,\n TargetDvcScopeId:string,\n TargetFQDN:string,\n TargetGeoCity:string,\n TargetGeoCountry:string,\n TargetGeoLatitude:real,\n TargetGeoLongitude:real,\n TargetGeoRegion:string,\n TargetHostname:string,\n TargetIpAddr:string,\n TargetOriginalAppType:string,\n TargetOriginalRiskLevel:string,\n TargetOriginalUserType:string,\n TargetPortNumber:int,\n TargetRiskLevel:int,\n TargetSessionId:string,\n TargetSimpleUsername:string,\n TargetUrl:string,\n TargetUserAadId:string,\n TargetUserAWSId:string,\n TargetUserId:string,\n TargetUserIdType:string,\n TargetUsername:string,\n TargetUsernameType:string,\n TargetUserOktaId:string,\n TargetUserPuid:string,\n TargetUserScope:string,\n TargetUserScopeId:string,\n TargetUserSid:string,\n TargetUserType:string,\n TargetUserUid:string,\n TargetUserUpn:string,\n TargetWindowsUsername:string,\n ThreatCategory:string,\n ThreatConfidence:int,\n ThreatField:string,\n ThreatFirstReportedTime:datetime,\n ThreatId:string,\n ThreatIpAddr:string,\n ThreatIsActive:bool,\n ThreatLastReportedTime:datetime,\n ThreatName:string,\n ThreatOriginalConfidence:string,\n ThreatOriginalRiskLevel:string,\n ThreatRiskLevel:int,\n User:string\n)[];\nEmptyAuthenticationTable", "version": 1 } } diff --git a/Parsers/ASimAuthentication/CHANGELOG/vimAuthenticationEmpty.md b/Parsers/ASimAuthentication/CHANGELOG/vimAuthenticationEmpty.md index 308e53bd6f1..5c903e41d06 100644 --- a/Parsers/ASimAuthentication/CHANGELOG/vimAuthenticationEmpty.md +++ b/Parsers/ASimAuthentication/CHANGELOG/vimAuthenticationEmpty.md @@ -1,5 +1,9 @@ # Changelog for vimAuthenticationEmpty.yaml +## Version 0.3.0 + +- (2026-04-06) Change SrcPortNumber type from string to int to align with documentation - [PR #13851](https://github.com/Azure/Azure-Sentinel/pull/13851) + ## Version 0.2.0 - (2026-03-17) Update empty parser alphabetically and align with columns from ASimTester.csv - [PR #13851](https://github.com/Azure/Azure-Sentinel/pull/13851) diff --git a/Parsers/ASimAuthentication/Parsers/vimAuthenticationEmpty.yaml b/Parsers/ASimAuthentication/Parsers/vimAuthenticationEmpty.yaml index e7c402d8049..39551e717b4 100644 --- a/Parsers/ASimAuthentication/Parsers/vimAuthenticationEmpty.yaml +++ b/Parsers/ASimAuthentication/Parsers/vimAuthenticationEmpty.yaml @@ -115,7 +115,7 @@ ParserQuery: | SrcIpAddr:string, SrcIsp:string, SrcOriginalRiskLevel:string, - SrcPortNumber:string, + SrcPortNumber:int, SrcRiskLevel:int, TargetAppId:string, TargetAppName:string,