Skip to main content
September 3, 2026
Question

Microsoft Sentinel Connector deployment failure

  • September 3, 2026
  • 3 replies
  • 37 views

I have been working on getting this connector set up for Sentinel.  When I deploy, there appears to be an issue with the connector build.  I get the following:

Failed to create required resources for data connector InvalidPayload:Data collection rule is invalid, [{"code":"InvalidInputSchema","message":"Custom input stream(s) 'Custom-OnePasswordEventLogs_CL' used with 'transformKql' must be defined in 'streamDeclarations'.","target":"properties.dataFlows[0]"}]

 

Is there something I’m missing about the deployment of this connector, or does the connector need an update?  I tried from both the Unified Portal in Defender, as well as the Azure side, and got the same results both way.  It does not appear to create any resources, other than the initial base table.

Microsoft indicated that support for the connector would came from 1Password, so reaching out here.

Thanks!

3 replies

September 11, 2026

Seeing the same error here. 
I went to raise an issue in the Sentinel GitHub but can see this was already raised:
1Password (Serverless) connector - potential ARM template bug · Issue #15031 · Azure/Azure-Sentinel

In this case, Microsoft have directed the reporter back to 1Password for a resolution. 

Will see if I can log a support case with 1Password to look into this. 

SB

September 16, 2026

1Password (Serverless) connector — deployment failure and working fix

Symptom

Installing the 1Password solution from Content Hub and clicking Connect on the 1Password (Serverless) connector fails with:

JSON

 

"InvalidPayload": "Data collection rule is invalid,
[{\"code\":\"InvalidInputSchema\",\"message\":\"Custom input stream(s) 'Custom-OnePasswordEventLogs_CL' used with 'transformKql' must be defined in 'streamDeclarations'.\",\"target\":\"properties.dataFlows[0]\"}]"

This matches Azure-Sentinel GitHub issue 15031, which Microsoft closed on the basis that the solution is partner-supported by 1Password.

Root cause

The published ARM template omits the streamDeclarations block. In azuredeploy_1Password_poller_connector.json, the Microsoft.Insights/dataCollectionRules resource nested inside resources[0].properties.mainTemplate.resources has dataCollectionEndpointId, destinations, and dataFlows — with a transformKql referencing Custom-OnePasswordEventLogs_CL — but never declares that stream. Azure Monitor rejects it at validation.

What doesn't work

Pre-creating the data collection rule manually with the correct stream declaration. The PUT succeeds, but Connect still fails identically — the connector builds and validates its own payload rather than reusing an existing DCR. The failure happens before any resource is touched, which is also why no failed deployment appears in the resource group's deployment history.

The fix, in three parts

1. Patch the ARM template

Inject streamDeclarations into the DCR resource, between destinations and dataFlows. The 32 columns match the OnePasswordEventLogs_CL table schema:

JSON

 

"streamDeclarations": {
"Custom-OnePasswordEventLogs_CL": {
"columns": [
{ "name": "TimeGenerated", "type": "datetime" },
{ "name": "uuid_s", "type": "string" },
{ "name": "session_uuid", "type": "string" },
{ "name": "timestamp", "type": "datetime" },
{ "name": "country", "type": "string" },
{ "name": "category", "type": "string" },
{ "name": "action_type", "type": "string" },
{ "name": "details", "type": "dynamic" },
{ "name": "target_user", "type": "dynamic" },
{ "name": "client", "type": "dynamic" },
{ "name": "location", "type": "dynamic" },
{ "name": "actor_uuid", "type": "string" },
{ "name": "actor_details", "type": "dynamic" },
{ "name": "actor_type", "type": "string" },
{ "name": "actor_account_uuid", "type": "string" },
{ "name": "account_uuid", "type": "string" },
{ "name": "user_type", "type": "string" },
{ "name": "user_account_uuid", "type": "string" },
{ "name": "action", "type": "string" },
{ "name": "object_type", "type": "string" },
{ "name": "object_uuid", "type": "string" },
{ "name": "object_details", "type": "dynamic" },
{ "name": "aux_id", "type": "int" },
{ "name": "aux_uuid", "type": "string" },
{ "name": "aux_details", "type": "dynamic" },
{ "name": "aux_info", "type": "string" },
{ "name": "session", "type": "dynamic" },
{ "name": "used_version", "type": "int" },
{ "name": "vault_uuid", "type": "string" },
{ "name": "item_uuid", "type": "string" },
{ "name": "user", "type": "dynamic" },
{ "name": "log_source", "type": "string" }
]
}
},

2. Deploy via custom template

Azure portal $\rightarrow$ Deploy a custom template $\rightarrow$ Build your own template in the editor $\rightarrow$ load the patched file. It takes a workspace name parameter only; no base URL or token at this stage.

3. Create the poller connectors via REST

The Connect button still fails after this, so create the three RestApiPoller connectors directly via PowerShell:

PowerShell

 

$subId = "<YOUR_SUBSCRIPTION_ID>"
$rg = "<YOUR_RESOURCE_GROUP>"
$workspace = "<YOUR_WORKSPACE_NAME>"
$token = "<YOUR_1PASSWORD_API_TOKEN>"
$baseUrl = "https://events.1password.com" # Or https://events.ent.1password.com for Enterprise

# Dynamically fetch the provisioned DCR and DCE ingestion URI
$dcr = Get-AzDataCollectionRule -ResourceGroupName $rg | Where-Object {$_.Name -like "Microsoft-Sentinel-1PasswordDCR-*"}
$immutableId = $dcr.ImmutableId

$dceName = ($dcr.DataCollectionEndpointId -split '/')[-1]
$dce = Get-AzDataCollectionEndpoint -ResourceGroupName $rg -Name $dceName
$dceUrl = $dce.LogIngestionEndpoint

$connectors = @(
@{ Name = "OnePasswordSignInEvents"; Endpoint = "$baseUrl/api/v2/signinattempts"; Window = 5 },
@{ Name = "OnePasswordAuditEvents"; Endpoint = "$baseUrl/api/v2/auditevents"; Window = 5 },
@{ Name = "OnePasswordItemUsageEvents"; Endpoint = "$baseUrl/api/v2/itemusages"; Window = 1 }
)

foreach ($c in $connectors) {
$uri = "https://management.azure.com/subscriptions/$subId/resourceGroups/$rg/providers/Microsoft.OperationalInsights/workspaces/$workspace/providers/Microsoft.SecurityInsights/dataConnectors/$($c.Name)?api-version=2023-02-01-preview"

$payload = @{
kind = "RestApiPoller"
properties = @{
connectorDefinitionName = "1Password-CodelessConnector"
dataType = "OnePasswordEventLogs_CL"
dcrConfig = @{
streamName = "Custom-OnePasswordEventLogs_CL"
dataCollectionEndpoint = $dceUrl
dataCollectionRuleImmutableId = $immutableId
}
auth = @{
type = "APIKey"
ApiKey = $token
ApiKeyName = "Authorization"
ApiKeyIdentifier = "Bearer"
}
request = @{
apiEndpoint = $c.Endpoint
httpMethod = "Post"
queryWindowInMin = $c.Window
queryTimeFormat = "yyyy-MM-ddTHH:mm:ssZ"
rateLimitQps = 1
retryCount = 3
timeoutInSeconds = 60
headers = @{ "Content-Type" = "application/json" }
queryParametersTemplate = '{"limit": 1000, "start_time": "{_QueryWindowStartTime}", "end_time": "{_QueryWindowEndTime}" }'
isPostPayloadJson = $true
}
response = @{
format = "json"
eventsJsonPaths = @('$.items')
}
paging = @{
pagingType = "NextPageToken"
nextPageParaName = "cursor"
nextPageTokenJsonPath = '$.cursor'
hasNextFlagJsonPath = '$.has_more'
}
}
} | ConvertTo-Json -Depth 10

$res = Invoke-AzRestMethod -Method PUT -Uri $uri -Payload $payload
Write-Host "$($c.Name) StatusCode: $($res.StatusCode)"
if ($res.StatusCode -notin 200,201) { $res.Content }
}

Two things that will catch you out

  • dataCollectionEndpoint must be the endpoint's log ingestion URL, not its resource ID. Passing the resource ID returns: "DataCollectionEndpoint must be an https:// URL whose host ends with .ingest.monitor.azure.com". Get it with (Get-AzDataCollectionEndpoint -ResourceGroupName $rg -Name $dceName).LogIngestionEndpoint.

  • The JSONPath values need single quotes in PowerShell, or $.items and $.cursor get expanded as variables and silently become empty.

  • Base URL is [https://events.1password.com](https://events.1password.com) for Business and [https://events.ent.1password.com](https://events.ent.1password.com) for Enterprise. Decode your token at jwt.ms and check the aud claim if unsure.

All three pollers return 201 and ingestion starts within 30 minutes.

September 17, 2026

Had a response from 1Password support:

We’re currently working on an issue, which is related to our Microsoft Sentinel integration. The team has identified a bug in the Sentinel integration that is causing the DCR validation error. This means that the serverless connector cannot be successfully deployed at present. Changing the Events API token or Base URL will not resolve this specific validation error, and there is currently no supported workaround. 
 
Work is underway on a fix, and our current estimate is approximately two weeks for resolution: around one week to implement and test the fix, followed by up to an additional week for Microsoft approval and publication through Microsoft Sentinel Content Hub.