Microsoft Sentinel Connector deployment failure
I have been working on getting this connector set up for Sentinel. When I deploy, there appears to be an issue with the connector build. I get the following:
Failed to create required resources for data connector InvalidPayload:Data collection rule is invalid, [{"code":"InvalidInputSchema","message":"Custom input stream(s) 'Custom-OnePasswordEventLogs_CL' used with 'transformKql' must be defined in 'streamDeclarations'.","target":"properties.dataFlows[0]"}]
Is there something I’m missing about the deployment of this connector, or does the connector need an update? I tried from both the Unified Portal in Defender, as well as the Azure side, and got the same results both way. It does not appear to create any resources, other than the initial base table.
Microsoft indicated that support for the connector would came from 1Password, so reaching out here.
Thanks!
