Skip to content

Support Sentinel data lake Kusto authentication - #942

Draft
Ian Hellen (ianhelle) wants to merge 1 commit into
mainfrom
fix/sentinel-data-lake-auth
Draft

Ian Hellen (ianhelle) wants to merge 1 commit into
mainfrom
fix/sentinel-data-lake-auth

Conversation

@ianhelle

Copy link
Copy Markdown
Contributor

Summary

  • pass Kusto authentication selections to az_connect using its supported auth_methods parameter
  • use the Kusto SDK's TokenCredential integration so endpoint metadata determines the correct token resource and tokens can refresh automatically
  • fix the certificate-authentication helper call in the same connection path
  • document querying Microsoft Sentinel lake-only and archived data through the Kusto provider
  • add regression coverage for the Sentinel data lake endpoint and authentication forwarding

Related to #914.

Validation

  • pytest tests/data/drivers/test_azure_kusto_driver.py -q — 70 passed
  • ruff check msticpy/data/drivers/azure_kusto_driver.py
  • ruff format --check msticpy/data/drivers/azure_kusto_driver.py
  • pylint msticpy/data/drivers/azure_kusto_driver.py ... — 10.00/10
  • full CI-configured mypy — 273 source files clean

Repo-wide pre-commit was also attempted. It reaches existing notebook Ruff failures unrelated to this change; the changed source and whitespace checks pass.

Live validation requested

This needs validation against an onboarded Microsoft Sentinel data lake workspace. The expected usage is:

lake_prov = mp.QueryProvider("Kusto")
lake_prov.connect(
    cluster="https://api.securityplatform.microsoft.com/lake/kql",
    database="<workspace-name>-<workspace-id>",
    auth_types=["cli", "interactive"],
)
result = lake_prov.exec_query("SigninLogs | take 10")

Forward configured authentication methods correctly and let the Kusto SDK discover the endpoint-specific token resource.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: f9623714-c248-43f6-a0ad-0fbf8c8b122c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant