Skip to content

Feature/sap etd users entity#14089

Merged
v-atulyadav merged 3 commits into
Azure:masterfrom
MartinPankraz:feature/sap-etd-users-entity
Apr 21, 2026
Merged

Feature/sap etd users entity#14089
v-atulyadav merged 3 commits into
Azure:masterfrom
MartinPankraz:feature/sap-etd-users-entity

Conversation

@MartinPankraz
Copy link
Copy Markdown
Contributor

Changes

  • connector extended for Users entity
  • Analytic Rules: Expand Users entity in all 4 rules to extract UserAccountName and EmailAddresses
  • Entity Mappings: Added Account and Mailbox entity mappings for email correlation in Sentinel incidents

MartinPankraz and others added 2 commits April 16, 2026 17:33
Expand the Alerts OData query with the new Users entity type to retrieve
user master data including email addresses for correlation in Sentinel.

Changes:
- PollerConfig: Added Users to  parameter on Alerts poller
- DCR: Added Users (dynamic) column to SAPETDAlerts_CL stream
- Table: Added Users (dynamic) column to SAPETDAlerts_CL schema
- Version bumped to 3.0.4

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
… (v3.0.4)

- Expand Users entity in all 4 analytic rules to extract UserAccountName and EmailAddresses
- Add Account and Mailbox entity mappings for email correlation
- Add SAP_UserEmail to custom details
- Include Users column in LoginFromUnexpectedNetwork project clause
- Bump analytic rule versions
- Rebuild solution package 3.0.4

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@MartinPankraz MartinPankraz requested review from a team as code owners April 17, 2026 11:34
The analytic rules now mv-expand Users for email extraction,
but the KQL validation custom table definition was missing this column.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@MartinPankraz MartinPankraz requested a review from a team as a code owner April 17, 2026 11:42
@v-maheshbh v-maheshbh added the Solution Solution specialty review needed label Apr 17, 2026
@MartinPankraz
Copy link
Copy Markdown
Contributor Author

connector functional after Users entity add:
image

@v-atulyadav v-atulyadav merged commit 4bb0447 into Azure:master Apr 21, 2026
36 checks passed
@MartinPankraz MartinPankraz deleted the feature/sap-etd-users-entity branch April 21, 2026 07:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants