Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve query if column is not present #11197

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dridderhof
Copy link
Contributor

The columns you are getting the error are specific to DDOS protection diagnostic logs are not part of the official schema:

Required items, please complete

Change(s):

  • Update AttackSourcesPPSThreshold.yaml

Reason for Change(s):

  • Analytics rule wizard validation fails with message "'summarize' operator: Failed to resolve scalar expression name 'destPublicIpAddress_s'"

Version Updated:

  • Yes
  • Analytic rule template update

Testing Completed:

  • Need help; DDoS test is planned for week of 14th October, this will validate if the rule functions.

Checked that the validations are passing and have addressed any issues that are present:

  • See guidance below

Issue snippit:
image

Analytic rule fails when column is not present
@dridderhof dridderhof requested review from a team as code owners September 30, 2024 11:12
@v-prasadboke v-prasadboke self-assigned this Sep 30, 2024
@v-prasadboke v-prasadboke added the Solution Solution specialty review needed label Sep 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Solution Solution specialty review needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants