Skip to content

Commit 5f93815

Browse files
committed
gis-9099 add microsoft sentinel to one vendor flow
1 parent 532bf3d commit 5f93815

File tree

2 files changed

+3
-3
lines changed

2 files changed

+3
-3
lines changed

uncoder-core/app/translator/platforms/microsoft/const.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@
5353
"group_id": "microsoft-defender",
5454
}
5555

56-
MICROSOFT_QUERY_TYPES = {_SENTINEL_KQL_QUERY, _SENTINEL_KQL_RULE}
56+
MICROSOFT_SENTINEL_QUERY_TYPES = {_SENTINEL_KQL_QUERY, _SENTINEL_KQL_RULE}
5757

5858
microsoft_defender_query_details = PlatformDetails(**MICROSOFT_DEFENDER_DETAILS)
5959
microsoft_sentinel_query_details = PlatformDetails(**MICROSOFT_SENTINEL_QUERY_DETAILS)

uncoder-core/app/translator/translator.py

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
from app.translator.core.render import QueryRender
99
from app.translator.managers import ParserManager, RenderManager, parser_manager, render_manager
1010
from app.translator.platforms.elasticsearch.const import ELASTIC_QUERY_TYPES
11-
from app.translator.platforms.microsoft.const import MICROSOFT_QUERY_TYPES
11+
from app.translator.platforms.microsoft.const import MICROSOFT_SENTINEL_QUERY_TYPES
1212
from app.translator.platforms.roota.parsers.roota import RootAParser
1313
from app.translator.platforms.sigma.mapping import sigma_rule_mappings
1414
from app.translator.tools.decorators import handle_translation_exceptions
@@ -36,7 +36,7 @@ def __get_render(self, target: str) -> QueryRender:
3636

3737
@staticmethod
3838
def __is_one_vendor_translation(source: str, target: str) -> bool:
39-
vendors_query_types = [ELASTIC_QUERY_TYPES, MICROSOFT_QUERY_TYPES]
39+
vendors_query_types = [ELASTIC_QUERY_TYPES, MICROSOFT_SENTINEL_QUERY_TYPES]
4040
for vendor_query_types in vendors_query_types:
4141
if source in vendor_query_types and target in vendor_query_types:
4242
return True

0 commit comments

Comments
 (0)