undefined "Observable" type in field mapping exercise of Microsoft Graph Security API Alert to SI

mkmphasis
Tera Contributor

Under the field mapping section of Microsoft Graph security API alert profile, when mapping the MS Defender's alert's evidence attributes for App names to Observables on Security Incident we get undefine "Observable" type.

 

How can I map all the required evidences/Assets details that we are receiving from Microsoft graph security api payload to the observables related list of Security Incident ?

 

Do we need to create any new Observable types to resolve this issue ?

0 REPLIES 0