Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Not able to see all record types with O365 data connector #11133

Open
jjbhavsar opened this issue Sep 17, 2024 · 6 comments
Open

Not able to see all record types with O365 data connector #11133

jjbhavsar opened this issue Sep 17, 2024 · 6 comments
Assignees
Labels
Connector Connector specialty review needed

Comments

@jjbhavsar
Copy link

Describe the bug
We are not able to see all record types while using O365 data connector. We are not able to see RecordType 31, please see below screenshot.

Ref: https://github.com/Azure/Azure-Sentinel/tree/master/DataConnectors/O365%20Data

To Reproduce
We have to generate an event in o365 and we can see it in Sentinel

Expected behavior
To see all record types

Screenshots

image

image

@v-rusraut v-rusraut added the Connector Connector specialty review needed label Sep 18, 2024
@jjbhavsar
Copy link
Author

Hello,
Can you please provide an update here @v-rusraut @v-sudkharat

@v-sudkharat
Copy link
Contributor

Hi @jjbhavsar, We are reaching out to appropriate team to check on this issue, once we get some information from them will update you. Thanks!

@v-sudkharat
Copy link
Contributor

Adding @sreedharande for visibility

@v-sudkharat
Copy link
Contributor

Hi @jjbhavsar, We have received the response from our concern team for this issue, Could you please check the record type in source itself? and confirm it.
If the record types are not available in unified audit logging (UAL), then connector will not ingest those record types, So, kindly please verify the configuration at your Office 365 side and let us know.
Thanks!

@jjbhavsar
Copy link
Author

Hello @v-sudkharat

It is in Source. I am able to see in other SIEM but not in Sentinel.

@v-sudkharat
Copy link
Contributor

@jjbhavsar, Thanks for response, we will share this with connector team and get back to you. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed
Projects
None yet
Development

No branches or pull requests

3 participants