--- name: asim-parser-creator-orchestrator description: Orchestrates the creation and validation of a new ASIM schema parser. Use this skill when asked to create a new ASIM parser. requiredSkills: - az-cli-command-runner - asim-parser-user-prompter - asim-parser-create-parser - asim-parser-validator - asim-parser-create-parameter-parser - asim-parser-filter-validator - asim-parser-la-deployer - asim-parser-github-pr-packager - log-analytics-workspace-queryer --- # Create a new ASIM parser You are a Microsoft Sentinel expert responsible for creating ASIM schema parsers. An ASIM schema parser is a KQL function that transforms data from source tables into the target ASIM schema. ## Context to maintain Throughout the entire workflow, retain and pass the following information between steps: - **Workspace ID** — gathered during requirements, needed for validation, deployment, and querying. - **Source table name** — gathered during requirements, needed for parser creation and validation. - **Target ASIM schema name** — determined during requirements, needed in every subsequent step. - **Event vendor and event product** — needed for file naming and metadata. - **Parameter-less parser file path** — `ASim.kql`, produced in Step 2. - **Parameterized parser file path** — `vim.kql`, produced in Step 5. ## Step 1: Verify Azure CLI authentication Before any queries or deployments, use the `az-cli-command-runner` skill to run `az account show`. If it returns an error indicating the user is not logged in, ask the user to run `az login` before continuing. This prevents authentication failures later in the workflow. ## Step 2: Requirements gathering Ask the user for the information needed to create a new ASIM parser. Use the `asim-parser-user-prompter` skill to guide you through gathering requirements from the user. Before proceeding to Step 3, verify that you have collected: the source documentation link, the source table name, the Log Analytics workspace ID, and the target ASIM schema. ## Step 3: Create the initial parameter-less version of the ASIM parser Based on the schema determined and the requirements gathered, create an initial version of a new ASIM parser. Use the `asim-parser-create-parser` skill to generate the initial version of the parser. The output of this step is a file named `ASim.kql`. ## Step 4: Validate the parser After the initial version of the parser is generated, validate it. Use the `asim-parser-validator` skill to run both validations: 1. **Schema validation** using `ASimSchemaTester` — checks that output columns match the ASIM schema. 2. **Data validation** using `ASimDataTester` — checks that column values are correctly mapped and formatted. Both validations must be run before proceeding. ## Step 5: Refinement loop After validation, refine the parser based on the validation results. Repeat the following cycle: 1. Fix errors identified by the validator in the parser `.kql` file. 2. Re-run **both** `ASimSchemaTester` and `ASimDataTester` using the `asim-parser-validator` skill. 3. Check the results. **Exit criteria:** Proceed to Step 6 when there are no Error-level `(0)` results from either validation. **Iteration limit:** If after 5 refinement cycles there are still Error-level results, stop and present the remaining errors to the user for manual review before continuing. ## Step 6: Create the parameterized version of the ASIM parser Create a version of the ASIM parser that accepts parameters, allowing for more flexible and reusable querying. Use the `asim-parser-create-parameter-parser` skill to generate the parameterized version. The output of this step is a file named `vim.kql`. After creating the parameterized parser, repeat Step 4 (validation) and Step 5 (refinement loop) against this new parser to ensure the added parameters and filters do not introduce errors. ## Step 7: Validate filtering parameters Run the filter validation tests against the parameterized parser to confirm that each filtering parameter behaves correctly. Use the `asim-parser-filter-validator` skill, passing the parameterized parser file (`vim.kql`), the schema name, and the workspace ID. If any filter tests fail, fix the parameterized parser and re-run the filter validation until all tests pass. Apply the same 5-iteration limit as Step 5 — if failures persist, present them to the user for manual review. ## Step 8: Ask the user what they want to do with the parser After parser creation, ask the user what they want to do next. Present two options: ### Option A: Deploy to Log Analytics workspace Use the `asim-parser-la-deployer` skill to deploy both parser files (`ASim...kql` and `vim...kql`) to the user's LA workspace. ### Option B: Package as a GitHub PR Use the `asim-parser-github-pr-packager` skill to package the parser into a GitHub PR for the Azure-Sentinel repository. The user may choose one or both options. ## Step 9: Report After the workflow is complete, present a summary report to the user that includes: | Section | Details | | --------------------------------------- | ------------------------------------------------------------------------------------------------- | | **Source column → ASIM field mappings** | A table of all source columns and the ASIM fields they were mapped to | | **Schema** | The target ASIM schema name and version | | **Vendor / Product** | The event vendor and event product | | **Files produced** | Full file paths of the parameter-less (`ASim...kql`) and parameterized (`vim...kql`) parser files | | **Validation warnings accepted** | Any Warning-level `(1)` results that were reviewed and accepted | | **Deployment / PR status** | Result of the deployment or PR creation step |