-
Notifications
You must be signed in to change notification settings - Fork 407
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
zoom update to ECS 1.11.0 #1430
Conversation
5570a16
to
5b77310
Compare
💚 Build Succeeded
Expand to view the summary
Build stats
Test stats 🧪
Trends 🧪 |
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
@@ -22,7 +22,3 @@ processors: | |||
fields: [message] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
As part of #670 could you migrate the json decode step into the ingest node pipeline?
- change setting ecs.version to pipeline
5b77310
to
e4c8634
Compare
@@ -18,11 +18,4 @@ tags: | |||
publisher_pipeline.disable_host: true | |||
{{/contains}} | |||
processors: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Somewhere in here I think we want to this in order to get a raw copy of the JSON sent to the webhook.
{{#if preserve_original_event}}
preserve_original_event: true
{{/if}}
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
For consistency with the other packages it should probably also set a tag with the preserve original event.
- remove extraneous filebeat json processor - update tests - change ecs field definitions to use external definitions Relates elastic#670
e4c8634
to
ccbfe0c
Compare
45c7002
to
87399f4
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
* Set ecs.version to 1.11.0 - change setting ecs.version to pipeline - remove extraneous filebeat json processor - update tests - change ecs field definitions to use external definitions - add preserve original event option and set tag Relates elastic#670
What does this PR do?
ecs.version
to 1.11.0Checklist
changelog.yml
file.- [ ] If I'm introducing a new feature, I have modified the Kibana version constraint in my package'smanifest.yml
file to point to the latest Elastic stack release (e.g.^7.13.0
).Related issues