Closed Jt3kt closed 4 years ago
Thank you so much! I’ll review these either tonight or tomorrow afternoon, this is what I was hoping for. 👍👍
Looking at it, I'm going to split the function Update-LrCaseEarliestEvidenceFromDrilldown into two functions.
Update-LrCaseEarliestEvidenceFromDrilldown and Update-LrCaseEarliestEvidence
With that change the FromDrilldown function will make use of the Update-LrCaseEarliestEvidence function while adding the ability to directly update a cases evidence marker for other scenarios.
Going to send an updated pull request for these functions. No need to muddy the waters.
Two new functions for the LogRhythm/Case module. Let me know which points may not meet the coding standard, I went to match your examples.
New Functions: Get-LrCaseEarliestEvidence Update-LrCaseEarliestEvidenceFromDrilldown