Prompts the user for inputs to create a new ASIM schema parser. Use this skill when you need to gather information from the user to create a new ASIM parser.
67
80%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./.github/skills/asim-parser-user-prompter/SKILL.mdYou will need to ask the user for various information before you can create a new ASIM parser. This skill will guide you on what information to ask for and how to ask for it.
The source data type is the type of data that the ASIM parser will be parsing. Ask the user to provide a link to the source's documentation.
Ask the user to provide the name of the table where the data type is stored in Microsoft Sentinel.
Ask the user to provide the Log Analytics workspace ID where the table is stored. This workspace ID is a GUID.
Validate the workspace and table name by querying the workspace using the log-analytics-workspace-queryer skill. Provide the skill with the workspace ID and the table name as the query. If the query fails, ask the user to provide the information again.
Based on the documentation and the table name, evaluate what ASIM schema the source data type maps to. The available schemas are listed at: https://learn.microsoft.com/en-us/azure/sentinel/normalization-about-schemas. Choose from the schemas there.
If you are not sure which schema it maps to, inform the user that you cannot create a parser without knowing the target ASIM schema.
fd26ba7
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.