-
Notifications
You must be signed in to change notification settings - Fork 561
cloudflare_logpush: Normalise event.severity #17516
Copy link
Copy link
Open
Labels
Category: Integration qualityCategory: Quality used for SI planningCategory: Quality used for SI planningIntegration:cloudflare_logpushCloudflare LogpushCloudflare LogpushTeam:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]
Metadata
Metadata
Assignees
Labels
Category: Integration qualityCategory: Quality used for SI planningCategory: Quality used for SI planningIntegration:cloudflare_logpushCloudflare LogpushCloudflare LogpushTeam:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]
Type
Fields
Give feedbackNo fields configured for issues without a type.
As noted in #12662, the cloudflare_logpush integration also requires normalising
event.severityvalues according to below scale to conform to Elastic Security detection rules:Example implementation for other integrations: #13955