Skip to content

Commit ce3dac3

Browse files
committed
fix: change references to deviceid to rawId
1 parent 4c324fa commit ce3dac3

4 files changed

Lines changed: 4 additions & 7 deletions

File tree

plugins/MicrosoftDefender/v1/dataStreams/Vulnerabilities.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313
"expandInnerObjects": true,
1414
"endpointPath": "runHuntingQuery",
1515
"postBody": {
16-
"Query": "DeviceTvmSoftwareVulnerabilities | where DeviceId in ({{objects.map(o => {return `\"${o.deviceid}\"`}).join(\",\")}})",
16+
"Query": "DeviceTvmSoftwareVulnerabilities | where DeviceId in ({{objects.map(o => {return `\"${o.rawId}\"`}).join(\",\")}})",
1717
"Timespan": "{{timeframe.enum != \"none\" ? `${timeframe.start}/${timeframe.end}` : \"\" }}"
1818
},
1919
"pathToData": "results",

plugins/MicrosoftDefender/v1/dataStreams/devices.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313
"expandInnerObjects": true,
1414
"endpointPath": "runHuntingQuery",
1515
"postBody": {
16-
"Query": "DeviceInfo | where DeviceId in ({{objects.map(o => {return `\"${o.deviceid}\"`}).join(\",\")}}) | summarize arg_max(Timestamp, *) by DeviceId"
16+
"Query": "DeviceInfo | where DeviceId in ({{objects.map(o => {return `\"${o.rawId}\"`}).join(\",\")}}) | summarize arg_max(Timestamp, *) by DeviceId"
1717
},
1818
"pathToData": "results",
1919
"getArgs": [],

plugins/MicrosoftDefender/v1/dataStreams/recommendations.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313
"expandInnerObjects": true,
1414
"endpointPath": "runHuntingQuery",
1515
"postBody": {
16-
"Query": "DeviceTvmSecureConfigurationAssessment | where DeviceId in ({{objects.map(o => {return `\"${o.deviceid}\"`}).join(\",\")}}) | join kind=leftouter (DeviceTvmSecureConfigurationAssessmentKB) on ConfigurationId | project DeviceId, DeviceName, Timestamp, ConfigurationId, ConfigurationName, ConfigurationCategory, ConfigurationSubcategory, ConfigurationImpact, RiskDescription, RemediationOptions, IsApplicable, IsCompliant, Tags",
16+
"Query": "DeviceTvmSecureConfigurationAssessment | where DeviceId in ({{objects.map(o => {return `\"${o.rawId}\"`}).join(\",\")}}) | join kind=leftouter (DeviceTvmSecureConfigurationAssessmentKB) on ConfigurationId | project DeviceId, DeviceName, Timestamp, ConfigurationId, ConfigurationName, ConfigurationCategory, ConfigurationSubcategory, ConfigurationImpact, RiskDescription, RemediationOptions, IsApplicable, IsCompliant, Tags",
1717
"Timespan": "{{timeframe.enum != \"none\" ? `${timeframe.start}/${timeframe.end}` : \"\" }}"
1818
},
1919
"pathToData": "results",

plugins/MicrosoftDefender/v1/indexDefinitions/default.json

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,10 +18,7 @@
1818
"OSVersion",
1919
"PublicIP",
2020
"OSBuild",
21-
"OSArchitecture",
22-
{
23-
"deviceid": "DeviceId"
24-
}
21+
"OSArchitecture"
2522
]
2623
}
2724
}

0 commit comments

Comments
 (0)