Skip to content

update: extend logpoint_m365_mapping with additional fields and operation mapping#22

Open
tastysammich wants to merge 1 commit intologpoint:mainfrom
tastysammich:patch-2
Open

update: extend logpoint_m365_mapping with additional fields and operation mapping#22
tastysammich wants to merge 1 commit intologpoint:mainfrom
tastysammich:patch-2

Conversation

@tastysammich
Copy link
Copy Markdown
Contributor

Description

This PR updates the logpoint_m365_mapping dictionary to include additional Microsoft 365 fields and align the mapping even more closely with Logpoint’s schema.

Changes

  • Added support for Applicationapplication_id
  • Added support for ObjectIdobject_id
  • Added support for RequestTyperequest_type
  • Updated Operation mapping from "operation" to "action" for consistency
  • Retained existing mappings for backward compatibility

These changes aim to improve coverage of M365 event fields in Logpoint backend mappings for more accurate normalization and reducing ambiguity in field naming (& further providing more context for downstream queries and analytics). Please let me know if there's a need to work on an alternative solution with the operation field or any other field to bridge this change well, thank you for working with me on all this! 😃

Added some additional mappings that could be yielded through m365 logs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant