New Defender Plugin#55
Conversation
vinbab
left a comment
There was a problem hiding this comment.
@jame2O Alerts data stream
- Alerts: Error message when Status is New
2) Alerts: Timeframe column needs to be on the Timeframe tab
3) let's order the columns, mimic the portal, everything else is hidden:
- Alert name
- Tags
- Severity
- Integration state
- Status
- Category
- Detection source
- Impacted Assets
- First activity
- Last activity
- Policy name
- Classification
- Determination
- Assigned To
- Workspace
- Cloud Scopes
- When I change the time column to Last Update Time, I get this error
vinbab
left a comment
There was a problem hiding this comment.
@jame2O change the order of the columns to mimic the portal, and hide everything else:
- Name
- IP
- Criticality
- Device category
- Device type
- Domain
- Device AAD id
- Risk Level
- Exposure level
- OS platform
- OS version
- Sensor health state
- Onboarding status
- Discovery sources
- Last device update
- Tags
- Device Role
- Managed by
- Managed by status
- Migration status
- Cloud platforms
vinbab
left a comment
There was a problem hiding this comment.
@jame2O Incidents data stream.
- Move the timeframe column to Timeframe tab.
- Timeframe options: like in Alerts, not all data/time fields are in the list. Is that a fixed list you are manually populating?
- order the columns like in the portal, hiding all others:
- Incident name
- Incident id
- Priority score
- Tags
- Severity
- Investigation state
- Categories
- Impacted assets
- Active alerts
- Service sources
- Detection sources
- Last update time
- Last activity
- Policy name
- Data sensitivity
- Status
- Assigned to
- Classification
- Determination
- Device groups
- Creation time
- Workspaces
- Cloud Scopes
vinbab
left a comment
There was a problem hiding this comment.
@jame2O Recommendations data stream:
- can you add the sourceId to the Device Name
Order the columns like this (hiding all others):
- Risk description
- Device Name
- Timestamp
- Configuration Name
- Configuration Category
- Configuration Subcategory
- Configuration Impact
- Remediation Options
- Is Applicable
- Is Compliant
Updated README.md for Microsoft Defender plugin to clarify authentication requirements, error handling, and dashboard descriptions.
vinbab
left a comment
There was a problem hiding this comment.
@jame2O final tweaks, then I'll Approve
- device is lowercase in donut. Should be lowercase
- Change the device icon to
- Update Cockpit from this one on Community Plugin Validation https://app.squaredup.com/dashboard/dash-z4CN8D9bgegxdqNhmqEX
clarkd
left a comment
There was a problem hiding this comment.
All looks good. Happy to not use rawId for now, but worth noting it would be a breaking change in the future.
Thanks, I've got this in my list of things to add post-release along with better error communication. Thanks for jumping on this so quickly! :) |
🧩 Plugin PR Summary📦 Modified Plugins
📋 Results
🔍 Validation Details✅
|
🔌 Plugin overview
🖼️ Plugin screenshots
Plugin configuration
Default dashboards
🧪 Testing
📚 Checklist