Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
379 commits
Select commit Hold shift + click to select a range
b745a7e
Remove default_pipeline change from Readmes for DGA, PAD, and LotL (#…
jmcarlock Sep 8, 2025
2ab6f6c
Add period to test config
jsoriano Sep 9, 2025
761d622
[o365] Improve permissions documentation (#15228)
chrisberkhout Sep 9, 2025
252f28a
[Kafka] Remove unused mapping fields (#15225)
agithomas Sep 9, 2025
aee01a4
Support special chars in interface name (#15242)
bhapas Sep 9, 2025
50c274f
Update `queue.filled.pct.events` to `queue.filled.pct` (#15244)
khushijain21 Sep 9, 2025
189ce33
Use journald input by default when running system integration for Deb…
pierrehilbert Sep 9, 2025
f200413
[Cloud Asset Inventory] Azure cloud_connectors_federated_identity typ…
amirbenun Sep 9, 2025
05fe552
[island_browser][device] Add island_browser device datastream (#15162)
janvi-elastic Sep 10, 2025
78ec5bf
[microsoft_defender_endpoint,m365_defender] extract process.name from…
mohitjha-elastic Sep 10, 2025
746af75
[cel] Add options for OAuth2 user/password (#15210)
chrisberkhout Sep 10, 2025
4f82f05
sentinel_one: add rally benchmark (part 2) (#15250)
navnit-elastic Sep 10, 2025
d79da75
[httpjson] Add options for OAuth2 user/password (#15211)
chrisberkhout Sep 10, 2025
823273b
CODEOWNERS: sort list (#15260)
efd6 Sep 10, 2025
5f7ee6a
[statsd_input] Make StatsD input package GA (#15125)
mykola-elastic Sep 10, 2025
9a2ed98
Change stack version requirements due to the breaking changes (#15268)
rdner Sep 10, 2025
5e8f959
[Cloud Asset Inventory] Cloud Connectors Align to CSPM Azure (#15264)
amirbenun Sep 10, 2025
6e6e232
[Cloud Security Posture] Support Azure cloud connector (#15255)
amirbenun Sep 10, 2025
744672e
[Cloud Security] Add Cloud Connectors credential option for Cloud Ass…
seanrathier Sep 10, 2025
74da98a
[Security AI Prompts] Add prompts for value report (#15213)
stephmilovic Sep 10, 2025
95ac724
box_events: add limit parameter and pagination (#15257)
chemamartinez Sep 10, 2025
9637849
rm knowledgeHistory (#15281)
stephmilovic Sep 10, 2025
adbd14b
[island_browser][user] Add island_browser user datastream (#15109)
janvi-elastic Sep 11, 2025
eb19498
[Zscaler ZPA] Add Convert conditions (#15131)
SimonKoetting Sep 11, 2025
4c355ef
[AWS CloudTrail] Map `aws.cloudtrail.recipient_account_id` to `cloud.…
moxarth-rathod Sep 11, 2025
fa1c3f9
Update the BitDefender Integration documentation (#15256)
alaudazzi Sep 11, 2025
e7ac517
ti_crowdstrike: add agentless deployment
mohitjha-elastic Sep 11, 2025
b10fbe7
elastic_security: add support for conditional required fields to hand…
mohitjha-elastic Sep 11, 2025
866e5d8
chore: update pkgs in .github/ISSUE_TEMPLATE/integration_*.yml (#15284)
github-actions[bot] Sep 11, 2025
538a4ca
Update ownership of cloudtrail to elastic/security-service-integratio…
kcreddy Sep 11, 2025
c7ee303
update native misconfiguration transform retention to 26h (#15270)
maxcold Sep 11, 2025
cb79853
Fix processing of crowdstrike.User.Name field (#15272)
chemamartinez Sep 11, 2025
3110fd4
build(deps): bump golang.org/x/tools from 0.36.0 to 0.37.0 (#15289)
dependabot[bot] Sep 11, 2025
a486bb1
Updated JSON indentation + added JSON tag on Valid JSON (#15076)
animehart Sep 11, 2025
963f3f4
{mimecast, carbon_black_cloud}: Add processor to remove the fields ad…
moxarth-rathod Sep 12, 2025
bc0338f
[Kafka] Add system tests for the datasets (#15243)
agithomas Sep 12, 2025
d43ffbc
Update the Memcached integration documentation (#15258)
alaudazzi Sep 12, 2025
2702b41
[O365 Metrics] Fix Readme (#15221)
Linu-Elias Sep 12, 2025
2867ffb
Update MySQL Integration documentation with the required privileges (…
alaudazzi Sep 12, 2025
6ffce0f
[O365_metrics] Fix Dashboards (#15259)
Linu-Elias Sep 12, 2025
73919d6
[Elastic Agent] Remove otelconsumer from Agent metrics dashboard (#15…
belimawr Sep 12, 2025
e7adea3
refactor!(beyondinsight_password_safe): asset data stream (#15103)
andrewkroh Sep 12, 2025
53ad61c
Update documentation to configure data view for dashboards (#15294)
sodhikirti07 Sep 12, 2025
082af3d
cel: add support for global header configuration (#15297)
efd6 Sep 14, 2025
a6399d4
jamf_protect: fix handling of tags in alerts data stream (#15311)
efd6 Sep 15, 2025
c780d01
feat!(beyondinsight_password_safe): standardize pipelines, disable dy…
andrewkroh Sep 15, 2025
40b6d8e
[O365] O365 UI layout improvements (#14922)
narph Sep 15, 2025
ec2ed89
swimlane: fix docker deployer for filestream input (#15301)
navnit-elastic Sep 15, 2025
be25d4e
[GCP VertexAI] Update panel links and dashboard screenshot (#15304)
muthu-mps Sep 15, 2025
7f0bf91
box_events: fix description of the interval setting (#15299)
chemamartinez Sep 15, 2025
0948111
Make security integrations GA (#15298)
moxarth-rathod Sep 15, 2025
4ff9014
Update the Cisco Umbrella Integration page (#15240)
alaudazzi Sep 15, 2025
c376a09
fix(azure logs) interim fix to support non-standard log events (#15205)
zmoog Sep 15, 2025
e71ed0e
fix(okta): prevent pagination when response len is under limit (#15310)
andrewkroh Sep 15, 2025
f7d18ff
feat: improve s3 access log parsing along with documentation updates …
Kavindu-Dodan Sep 15, 2025
a8b9678
snyk: fix parameter handling and allow issue update ingestion (#15239)
efd6 Sep 15, 2025
da7f3ca
Update osquery codeowner (#15008)
mjwolf Sep 15, 2025
9e9da32
o365: tolerate changed API next page URI behaviour (#15325)
efd6 Sep 16, 2025
11c0e1c
Update documentation on integration testing (#15009)
mjwolf Sep 16, 2025
9a7410c
Kafka consumer producer (#15099)
stefans-elastic Sep 16, 2025
419b018
sysdig: Fix the OOM kill issue for vulnerability data stream by dropp…
brijesh-elastic Sep 16, 2025
1d03cfa
[postgresql] OTel Content pack (#15035)
devamanv Sep 16, 2025
400a139
[vsphere] add extra grok pattern to cover more log formats (#15274)
stefans-elastic Sep 16, 2025
b2ef7ff
Add logs stream support (#14846)
rdner Sep 16, 2025
5068ae8
[SOPHOS UTM] Add GeopIP conditions (#15130)
SimonKoetting Sep 16, 2025
1251971
docs!(beyondinsight_password_safe): Refresh readme, move variable (#1…
andrewkroh Sep 16, 2025
03627dc
[Cloud Security] update wiz ingest pipeline to set vulnerability.titl…
alexreal1314 Sep 16, 2025
e0ccf81
[Security Rules] Update security rules package to v9.1.7-beta.1 (#15349)
tradebot-elastic Sep 16, 2025
30f1321
Add data retention for elastic agent status_change_logs data stream (…
MichelLosier Sep 16, 2025
119a86f
fix: disable webhook probe for http_endpoint inputs (#15355)
andrewkroh Sep 16, 2025
f487638
[Security AI Prompts] Prompts package to 1.0.3 (#15358)
stephmilovic Sep 16, 2025
27a870e
sailpoint_identity_sc: pass events as serialised json strings (#15359)
efd6 Sep 17, 2025
35222aa
1password: add agentless deployment
mohitjha-elastic Sep 17, 2025
8fd8782
chore: update pkgs in .github/ISSUE_TEMPLATE/integration_*.yml (#15361)
github-actions[bot] Sep 17, 2025
7a13c41
checkpoint_email: Populate additional ECS fields for the event types …
brijesh-elastic Sep 17, 2025
f8fc66e
eset-protect: fixed 'invalid_grant' integration cel error (#15333)
eset-wael-alhashemi Sep 17, 2025
35dbdae
[osquery_manager] Update osquery to version 5.18.1 (#15321)
marc-gr Sep 17, 2025
3c176af
[Enhancement] Update categories for packages (#14571)
trisch-me Sep 17, 2025
5b593f6
[AWS GuardDuty] Add agentless deployment (#15312)
moxarth-rathod Sep 17, 2025
8f8783a
[CI] Move test dependencies to tools.go (#15353)
mrodm Sep 17, 2025
7cd30de
[Logstash integration] Plugin time spent per event calculations fix. …
mashhurs Sep 17, 2025
4dc154c
build(deps): bump github.com/elastic/package-registry (#15371)
dependabot[bot] Sep 17, 2025
70b658c
[Cloud Security] Add elastic connector id to azure (#15326)
seanrathier Sep 17, 2025
3af3d70
auth0: use elastic/stream v0.20.0 (#15373)
andrewkroh Sep 17, 2025
c924715
[ti_greynoise] Add GreyNoise detection rule filter note and integrati…
niraj-crest Sep 18, 2025
8eb5768
jamf_protect: respect preserve_original_event in alerts (#15360)
efd6 Sep 18, 2025
2d783d5
abnormal_ai: fix precision of abx_message_id field (#15336)
chemamartinez Sep 18, 2025
8b02420
zscaler_zpa: unify treatment of user fields (#15292)
chemamartinez Sep 18, 2025
cfe8712
[Security Rules] Update security rules package to v9.1.7 (#15389)
tradebot-elastic Sep 18, 2025
8301cba
o365: fix handling of error conditions when requesting work continuat…
efd6 Sep 18, 2025
03b6ee7
sysdig: add support for cspm data stream to collect compliance results
brijesh-elastic Sep 18, 2025
30cbfa8
[Github] - Added support for gcs and azure-blob-storage inputs for gi…
ShourieG Sep 18, 2025
399ac8f
[Logstash integration] Add current and peak connections metrics of el…
mashhurs Sep 18, 2025
88930ee
m365_defender: ensure $skip parameter is correctly formatted (#15392)
efd6 Sep 18, 2025
49f1fae
[island_browser][audit] Add island_browser audit datastream (#15319)
janvi-elastic Sep 18, 2025
60ac006
sentinel_one: Add support for application risk data stream and ilm po…
mohitjha-elastic Sep 19, 2025
b08affa
build(deps): bump gotest.tools/gotestsum from 1.12.3 to 1.13.0 (#15395)
dependabot[bot] Sep 19, 2025
f33e18a
build(deps): bump github.com/elastic/elastic-package (#15398)
dependabot[bot] Sep 19, 2025
3437ddd
[kafka] add system tests to consumer and producer data streams (#15334)
stefans-elastic Sep 19, 2025
32feed4
[citrix_adc] Fix grok processing to HTTPREQUEST & UDPFLOWSTAT in sslv…
robester0403 Sep 19, 2025
95b2cbc
snyk: Add latest transform to issue data stream. (#15377)
kcreddy Sep 22, 2025
285494a
aws: Add Config and Inspector transforms for extended protections (CD…
kcreddy Sep 22, 2025
542266b
microsoft_defender_cloud: Add assessment data stream to support Cloud…
brijesh-elastic Sep 22, 2025
eddc7d2
ti_abusech: add support for new dashboards and update deprecated visu…
mohitjha-elastic Sep 22, 2025
9c3a211
[Tenable SC] Add agentless deployment (#15364)
moxarth-rathod Sep 22, 2025
39a4aec
tenable_io: add severity option for vulnerability data stream (#15394)
chemamartinez Sep 22, 2025
a67fc9f
[cyera][classification] Add Cyera Classification datastream (#15031)
muskan-agarwal26 Sep 22, 2025
88871b0
Update installation instructions for lotl (#15405)
frozenmog Sep 22, 2025
78806ad
[updatecli] Update latest snapshot to 8.19.5-SNAPSHOT (#15410)
github-actions[bot] Sep 22, 2025
3dcf35b
[cisco_asa][bugfix] allow empty access-group (#15422)
vinit-chauhan Sep 22, 2025
d68f9ae
airlock_digital: Initial release of the airlock_digital with agent da…
sharadcrest Sep 22, 2025
2810d7c
added asset inventory category (#14758)
animehart Sep 22, 2025
751aa99
[ti_cyware_intel_exchange] Update Readme and add ioc_expiration_durat…
muskan-agarwal26 Sep 23, 2025
beaf4b5
crowdstrike: migrate to combined alerts endpoint (#15291)
navnit-elastic Sep 23, 2025
2640643
sentinel_one: updated README instructions for generating the API toke…
mohitjha-elastic Sep 23, 2025
9087a3a
chore: update pkgs in .github/ISSUE_TEMPLATE/integration_*.yml (#15428)
github-actions[bot] Sep 23, 2025
e9add78
[cyera][issue] Add Cyera Issue datastream (#15107)
muskan-agarwal26 Sep 23, 2025
024c12d
System auth timestamp fix (#14844)
Tacklebox Sep 23, 2025
bc1a78a
Added misconfiguration_workflow and vulnerability_workflow to related…
animehart Sep 24, 2025
f28e5ec
[elastic_agent] Prefer RSS for memory usage charts (#15315)
AndersonQ Sep 24, 2025
db74cb2
aws.cloudtrail: Add `user.name` to Cloudtrail's `UserAuthentication` …
kcreddy Sep 24, 2025
d92242c
proofpoint_tap: add agentless deployment
mohitjha-elastic Sep 24, 2025
fe651fe
trend_micro_vision_one: relocate common required options (#15427)
chemamartinez Sep 24, 2025
bd14069
[JumpCloud] Add source_lag_time configuration option (#15432)
moxarth-rathod Sep 24, 2025
56b1c49
[cyera][event] Add Cyera Event datastream (#15146)
muskan-agarwal26 Sep 24, 2025
5c7e9d2
[island_browser] Remove ILM Policy from user and device data streams …
janvi-elastic Sep 24, 2025
873224d
[filestream] Migrate package to input type (#12878)
jsoriano Sep 24, 2025
34b9ef5
crowdstrike: improve windows events mappings in FDR data stream (#15342)
navnit-elastic Sep 24, 2025
6c447ac
o365: fix error propagation within cel program (#15445)
efd6 Sep 24, 2025
ff17f81
Add new fields to support the DGA algorithm and integration of AI Ins…
apps-elastic-gigamon Sep 25, 2025
55439b6
[Cloudflare Logpush] - Added support for Azure Blob Storage input in …
ShourieG Sep 25, 2025
9c0c10f
[GitHub] - Added missing oauth2 toggle in audit data stream (#15463)
ShourieG Sep 25, 2025
81309e8
[k8s otel] Use k8seventsreceiver data for K8s Events panels (#15454)
ChrsMark Sep 25, 2025
d12eead
Fixing Aruba build CI (#15461)
qcorporation Sep 25, 2025
ed5ef4b
[syslog_router] Support Cisco IOS (#15456)
taylor-swanson Sep 25, 2025
226858a
Add Sandfly Security connector policy template (#15460)
seanstory Sep 25, 2025
422b34a
[cisco_nexus] Fix whitespace issue with grok pattern (#15468)
taylor-swanson Sep 25, 2025
e46f81d
ssi_some: prevent updating fleet health status to degraded (#15415)
navnit-elastic Sep 25, 2025
f56f971
airlock_digital: Add execution histories data-stream (#15079)
sharadcrest Sep 25, 2025
9e09eb3
microsoft_defender_endpoint: ensure $skip parameter is correctly form…
kcreddy Sep 26, 2025
e252e30
[Checkpoint Email] Add agentless deployment (#15450)
moxarth-rathod Sep 26, 2025
8a36033
[GCP Vertex AI] Prompt response logs datastream (#15435)
ishleenk17 Sep 26, 2025
fa0ef1f
microsoft_defender_endpoint: ensure `page_size` configuration is pres…
brijesh-elastic Sep 26, 2025
630c145
o365: Fix 429 due to multiple subscription start attempts. (#15476)
kcreddy Sep 26, 2025
15979d3
[cyera] Add ILM policy note inside Readme (#15478)
janvi-elastic Sep 26, 2025
65ee9e7
[sophos] Fix add_locale handling in xg data stream (#15482)
taylor-swanson Sep 26, 2025
006736f
update kafka documentation (#15390)
stefans-elastic Sep 29, 2025
ed69bdb
[Snyk] Add agentless deployment (#15474)
moxarth-rathod Sep 29, 2025
19fbc06
Add fields mapping for Qualys field cloudProvider (#15324)
clement-fouque Sep 29, 2025
1ded072
crowdstrike: migrate to combined hosts endpoint (#15419)
navnit-elastic Sep 29, 2025
1a52bf4
add AI Assistant in Asset Inventory prompts (#15393)
maxcold Sep 29, 2025
5d58b32
keeper_security_siem_integration: new integration package for Keeper …
jpkeepersecurity Sep 29, 2025
f5f460f
[Kafka] Add new dashboards and link the newly added dashboards (#15328)
agithomas Sep 30, 2025
074c3a1
initial (#15486)
animehart Sep 30, 2025
f9c70e3
build(deps): bump updatecli/updatecli-action from 2.92.0 to 2.93.0 (#…
dependabot[bot] Sep 30, 2025
1c2a5e5
chore: update pkgs in .github/ISSUE_TEMPLATE/integration_*.yml (#15494)
github-actions[bot] Sep 30, 2025
7408e7a
[Phase 1] Rename "Requirements" into "What do I need to use this inte…
alaudazzi Sep 30, 2025
e53d170
[Security AI Prompt] Update prompts for new integrations knowledge to…
jen-huang Sep 30, 2025
69b0d30
crowdstrike: add pipeline benchmark (#15499)
navnit-elastic Oct 1, 2025
8013e52
crowdstrike: add rally benchmark and fix ingest pipeline bugs (#15497)
navnit-elastic Oct 1, 2025
4d02ec9
[O365] Dashboard enhancements (#15503)
moxarth-rathod Oct 1, 2025
50dfc4f
updated H1s per SEO suggestions (#15397)
ketkee-aryamane Oct 1, 2025
42ff22b
[Cloud Security Posture] Bump links for 9.2 (#15508)
jeniawhite Oct 1, 2025
06671c8
airlock_digital: Add server activities datastream (#15106)
sharadcrest Oct 1, 2025
7fed8c8
Update billing docs link (#15488)
3kt Oct 2, 2025
6b8adbf
[aws_logs] Remove fixed value from event.dataset mapping (#15507)
zmoog Oct 2, 2025
62947fe
Github: update audit dashboards (#15498)
chemamartinez Oct 2, 2025
6b5bd9a
[CISCO Meraki] Handle 8021x_client_deauth events and identity field (…
srilumpa Oct 2, 2025
1df7268
[cisco_aironet]: enhance CLIENT_ADDED_TO_RUN_STATE log parsing (#15517)
ilyannn Oct 2, 2025
d4c5d59
[PANW] Fix broken link (#15504)
alaudazzi Oct 3, 2025
cd048c1
Azure_frontdoor: fix processing of events with N/A values (#15514)
chemamartinez Oct 3, 2025
908ceec
[Azure AI Foundry] Update dashboard panel with donut chart (#15329)
muthu-mps Oct 3, 2025
dea9fc2
feat(beyondtrust_pra): Use Unix timestamp for start_time (#14950)
andrewkroh Oct 3, 2025
735f5ab
Add GH workflow for making docs edit easier (#15128)
shmsr Oct 6, 2025
bdc961a
Remove AdHoc Views from system_otel dashboards (#15509)
girodav Oct 6, 2025
d8a5e6d
Add missing information on the HAProxy Integration documentation (#15…
alaudazzi Oct 6, 2025
0aee7a6
Fix workflow syntax (#15553)
shmsr Oct 6, 2025
1bf663f
[Azure Storage Account] Add `default_timegrain` configuration option …
zmoog Oct 6, 2025
3042784
[Security Rules] Update security rules package to v9.1.8-beta.1 (#15577)
tradebot-elastic Oct 7, 2025
1f867af
[Security Rules] Update security rules package to v9.1.8 (#15581)
tradebot-elastic Oct 7, 2025
682c81c
Add malware advisory type to GitHub security advisories data stream (…
clement-fouque Oct 7, 2025
47a06e1
sentinel_one: Update dashboards with new screenshots, navigation pane…
mohitjha-elastic Oct 7, 2025
5252ae3
[ibm_qradar] Initial release of IBM QRadar (#15302)
akshraj-crest Oct 7, 2025
d8db446
Improve GH workflow for docs edit automation (#15573)
shmsr Oct 7, 2025
2ab655d
ci: remove sonarqube (#15557)
v1v Oct 7, 2025
34df8c0
Improve GITHUB_STEP_SUMMARY rendering to summary (#15589)
shmsr Oct 7, 2025
c1f8d2e
sentinel_one: Add configuration option to filter results by Site IDs,…
brijesh-elastic Oct 8, 2025
54416e3
Kafka dashboards for consumer producer datasets (#15267)
stefans-elastic Oct 8, 2025
059ed57
ti_domaintools: add domainhotlist_feed and domainrisk_feed data strea…
briluza Oct 8, 2025
1be9c81
[cyera][datastore] Add Cyera Datastore datastream (#15207)
muskan-agarwal26 Oct 8, 2025
5adb6e6
chore: update pkgs in .github/ISSUE_TEMPLATE/integration_*.yml (#15600)
github-actions[bot] Oct 8, 2025
219bb48
[Netskope] Add multiple system tests for Transaction data stream (#14…
moxarth-rathod Oct 8, 2025
b124909
[azure_functions] Parse stringified 'properties' field in Azure Funct…
devamanv Oct 8, 2025
9613a7c
feat: add tags and processors support to GCP data streams (#14745)
Lucas-Feat Oct 8, 2025
908e69c
[ProxySG] Make sure the ECS fields are mapped properly
jrmolin Oct 8, 2025
b375d4c
Add `opentelemetry` category to OTEL integrations (#15475)
gpop63 Oct 8, 2025
4e4f2b9
Kubernetes.audit_logs: fix processing of Azure AKS audit logs (#15585)
chemamartinez Oct 8, 2025
51fe49d
[island_browser][compromised_credential] Add island_browser compromis…
janvi-elastic Oct 8, 2025
5811423
Update Vertex AI fields to snake case in pipeline (#15604)
ishleenk17 Oct 9, 2025
ce98afa
[airflow] Make Airflow package GA (#15287)
mykola-elastic Oct 9, 2025
3678543
[proxysg] update changelog and manifest to create new release
jrmolin Oct 9, 2025
34a7ece
ssi: lower format_version to the minimum supporting necessary features
brijesh-elastic Oct 10, 2025
365e8cf
Add `opentelemetry` category to otel pkgs (#15615)
gpop63 Oct 10, 2025
00c7a53
build(deps): bump golang.org/x/tools from 0.37.0 to 0.38.0 (#15620)
dependabot[bot] Oct 10, 2025
178e13c
[updatecli] Update latest snapshot to 8.19.6-SNAPSHOT (#15624)
github-actions[bot] Oct 10, 2025
38f4bcc
[updatecli] Update latest snapshot to 9.3.0-SNAPSHOT (#15625)
github-actions[bot] Oct 10, 2025
6f1a1a8
[citrix_adc] Parse addition message formats (#15598)
mjwolf Oct 10, 2025
7c2d2ef
{microsoft_defender_endpoint,m365_defender}.vulnerability: New API im…
kcreddy Oct 12, 2025
7051042
darktrace: handle nested defeat conditions in Darktrace models (#15552)
arvchristos Oct 13, 2025
18270cb
Improve documentation by avoiding redirecting to Metricbeat Metricset…
herrBez Oct 13, 2025
ffc8802
gcp: add support for parsing sensitive action notifications event in …
mohitjha-elastic Oct 14, 2025
fc9de39
[cisco_asa] Add support for IPv6 parsing in 302xxx messages (#15606)
mjwolf Oct 14, 2025
678ed33
[aws_billing] Bump version set in the transform destination pipeline …
mrodm Oct 14, 2025
596fe16
[Akamai] - Added initial interval restrictions for api requests (#15649)
ShourieG Oct 15, 2025
b483955
Update security-ai-prompts saved objects with new Bedrock system prom…
maxcold Oct 15, 2025
d113743
Remove hard-coded dataset value (#15653)
rdner Oct 15, 2025
89828a6
Remove startWith usage in condition to fix issues with certain versio…
pierrehilbert Oct 16, 2025
1f56202
Fix Yaml Syntax Issue (#15669)
pierrehilbert Oct 16, 2025
0c0d511
[O365] Improve documentation (#15660)
moxarth-rathod Oct 17, 2025
40a5084
update Asset Inventory (Entity Store) prompt (#15656)
maxcold Oct 17, 2025
3e069a1
[Network Beaconing Identification] Add destination.ip filter to beaco…
sodhikirti07 Oct 17, 2025
3e53d71
Set url parameter in gvm command (#15675)
mrodm Oct 17, 2025
32bb5c4
9.12 pre release integrations bump (#15676)
jeniawhite Oct 19, 2025
9ff5f98
[Security Rules] Update security rules package to v9.2.1-beta.1 (#15683)
tradebot-elastic Oct 20, 2025
b13ad98
[Security Rules] Update security rules package to v9.2.1 (#15687)
tradebot-elastic Oct 20, 2025
6c30d36
[Linux] Fix sourceField in system dashboard (#15688)
orestisfl Oct 20, 2025
11d4062
kubernetes_otel: update EDOT url (#15692)
florianl Oct 20, 2025
ad1b851
[Security AI Prompts] `ease` promptGroupId change (#15674)
stephmilovic Oct 20, 2025
2101851
checkpoint_firewall: update count types from integer to long
haetamoudi Oct 20, 2025
d39634b
[CI] Update GVM version (#15691)
mrodm Oct 21, 2025
532c964
Update the Cloud Asset Discovery documentation (#15705)
alaudazzi Oct 21, 2025
b03d358
entityanalytics_ad: improve field mappings for device entities (#15642)
efd6 Oct 22, 2025
8a42235
Update unique keys for latest issues transform to catch all updates (…
clement-fouque Oct 22, 2025
f75ddbe
microsoft_defender_endpoint: add support for oauth endpoint params (#…
chemamartinez Oct 22, 2025
dbf1e3e
Update codeowners for ess_billing package (#15317)
lalit-satapathy Oct 22, 2025
b41a50b
feat: expose sasl mechanism configuration in kafka_log package (#15647)
stefans-elastic Oct 22, 2025
343cf18
[Docs] Document enabling automatic installation for content packages …
vishaangelova Oct 22, 2025
e660777
citrix_waf: fix titles and descriptions in data stream manifest (#15709)
efd6 Oct 22, 2025
58fefb8
Remove updated_at field from latest issues transform unique keys. (#1…
clement-fouque Oct 22, 2025
f0b65ce
[O365] Add policy tests and benchmarks (#15554)
moxarth-rathod Oct 23, 2025
02e7703
add discovery.datasets to _otel packages owned by infraobs (#15664)
mykola-elastic Oct 23, 2025
ffa4ed6
Pleasant Password Server extraction improvements (#15666)
WildDogOne Oct 23, 2025
6e00355
[aws_vpcflow_otel] Content pack of EDOT Cloud Forwarder for AWS - VPC…
mykola-elastic Oct 23, 2025
6bd3578
[aws_elb_otel] Add AWS ELB logs content pack for OpenTelemetry (#15401)
gpop63 Oct 23, 2025
8bf7fb5
crowdstrike: add event categorization fields to process data in alert…
navnit-elastic Oct 23, 2025
d01f509
Kafka system tests variants (#15629)
stefans-elastic Oct 23, 2025
788aaa4
Update the Cloud Asset Discovery documentation (#15736)
alaudazzi Oct 23, 2025
e65e5d7
Add elastic agent alerting rule templates (#15572)
MichelLosier Oct 23, 2025
53b76df
Merge remote-tracking branches 'origin/main' and 'jsoriano/httpcheck-…
jsoriano Oct 23, 2025
17972ca
Update package with best practices
jsoriano Oct 23, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
2 changes: 1 addition & 1 deletion .buildkite/pipeline.publish.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# yaml-language-server: $schema=https://raw.githubusercontent.com/buildkite/pipeline-schema/main/schema.json

env:
SETUP_GVM_VERSION: "v0.5.2"
SETUP_GVM_VERSION: "v0.6.0"
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"
DOCKER_COMPOSE_VERSION: "v2.24.1"
DOCKER_VERSION: "false"
Expand Down
10 changes: 5 additions & 5 deletions .buildkite/pipeline.schedule-daily.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
name: integrations-schedule-daily

env:
SETUP_GVM_VERSION: "v0.5.2"
SETUP_GVM_VERSION: "v0.6.0"
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"

# The pipeline is triggered by the scheduler every day
Expand Down Expand Up @@ -34,7 +34,7 @@ steps:
env:
SERVERLESS: "false"
FORCE_CHECK_ALL: "true"
STACK_VERSION: 8.19.1-SNAPSHOT
STACK_VERSION: 8.19.6-SNAPSHOT
PUBLISH_COVERAGE_REPORTS: "true"
depends_on:
- step: "check"
Expand All @@ -48,7 +48,7 @@ steps:
env:
SERVERLESS: "false"
FORCE_CHECK_ALL: "true"
STACK_VERSION: 8.19.1-SNAPSHOT
STACK_VERSION: 8.19.6-SNAPSHOT
STACK_LOGSDB_ENABLED: "true"
PUBLISH_COVERAGE_REPORTS: "false"
depends_on:
Expand Down Expand Up @@ -86,13 +86,13 @@ steps:
if: |
build.env('TEST_PACKAGES_BASIC_SUBSCRIPTION') == "true"

- label: "Check integrations local stacks - Stack Version v9.2"
- label: "Check integrations local stacks - Stack Version v9.3"
trigger: "integrations"
build:
env:
SERVERLESS: "false"
FORCE_CHECK_ALL: "true"
STACK_VERSION: 9.2.0-SNAPSHOT
STACK_VERSION: 9.3.0-SNAPSHOT
PUBLISH_COVERAGE_REPORTS: "false"
depends_on:
- step: "check"
Expand Down
8 changes: 4 additions & 4 deletions .buildkite/pipeline.schedule-weekly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
name: integrations-schedule-weekly

env:
SETUP_GVM_VERSION: "v0.5.2"
SETUP_GVM_VERSION: "v0.6.0"
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"

# The pipeline is triggered by the scheduler every week
Expand All @@ -21,20 +21,20 @@ steps:
env:
SERVERLESS: "false"
FORCE_CHECK_ALL: "true"
STACK_VERSION: 8.19.1-SNAPSHOT
STACK_VERSION: 8.19.6-SNAPSHOT
PUBLISH_COVERAGE_REPORTS: "false"
ELASTIC_PACKAGE_DISABLE_ELASTIC_AGENT_WOLFI: "true"
depends_on:
- step: "check"
allow_failure: false

- label: "Check integrations local stacks and non-wolfi images for Elastic Agent - Stack Version v9.2"
- label: "Check integrations local stacks and non-wolfi images for Elastic Agent - Stack Version v9.3"
trigger: "integrations"
build:
env:
SERVERLESS: "false"
FORCE_CHECK_ALL: "true"
STACK_VERSION: 9.2.0-SNAPSHOT
STACK_VERSION: 9.3.0-SNAPSHOT
PUBLISH_COVERAGE_REPORTS: "false"
ELASTIC_PACKAGE_DISABLE_ELASTIC_AGENT_WOLFI: "true"
depends_on:
Expand Down
2 changes: 1 addition & 1 deletion .buildkite/pipeline.serverless.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# yaml-language-server: $schema=https://raw.githubusercontent.com/buildkite/pipeline-schema/main/schema.json

env:
SETUP_GVM_VERSION: "v0.5.2"
SETUP_GVM_VERSION: "v0.6.0"
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"
DOCKER_COMPOSE_VERSION: "v2.24.1"
DOCKER_VERSION: "false" # not required to set since system tests are not running yet
Expand Down
35 changes: 19 additions & 16 deletions .buildkite/pipeline.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# yaml-language-server: $schema=https://raw.githubusercontent.com/buildkite/pipeline-schema/main/schema.json
env:
SETUP_GVM_VERSION: "v0.5.2"
SETUP_GVM_VERSION: "v0.6.0"
DOCKER_COMPOSE_VERSION: "v2.24.1"
DOCKER_VERSION: "26.1.2"
KIND_VERSION: 'v0.27.0'
Expand Down Expand Up @@ -57,6 +57,24 @@ steps:
image: "${LINUX_AGENT_IMAGE}"
cpu: "8"
memory: "4G"
artifact_paths:
- tests-report.xml

- label: ":junit: Sources Junit annotate"
agents:
# requires at least "bash", "curl" and "git"
image: "docker.elastic.co/ci-agent-images/buildkite-junit-annotate:1.0"
depends_on:
- step: "check"
allow_failure: true
plugins:
- junit-annotate#v2.7.0:
artifacts: "tests-report.xml"
failed-download-exit-code: 0 # Not fail the build in case there are no XML files
report-skipped: true
always-annotate: false
run-in-docker: false
context: junit-sources

- label: "Trigger integrations"
key: "test-integrations"
Expand Down Expand Up @@ -85,21 +103,6 @@ steps:
build.env('BUILDKITE_PULL_REQUEST') != "false" &&
build.env('BUILDKITE_PIPELINE_SLUG') == "integrations"

- label: ":sonarqube: Continuous Code Inspection"
soft_fail: true # FIXME: Coverage is failing, remove this after solving the issue
timeout_in_minutes: 120
env:
VAULT_SONAR_TOKEN_PATH: "kv/ci-shared/platform-ingest/elastic/integrations/sonar-analyze-token"
agents:
image: "docker.elastic.co/cloud-ci/sonarqube/buildkite-scanner:latest"
cpu: "8"
memory: "4G"
command: ".buildkite/scripts/run_sonar_scanner.sh"
artifact_paths:
- build/test-coverage/coverage_merged.xml
if: |
build.env('BUILDKITE_PIPELINE_SLUG') == "integrations"

- label: ":junit: Junit annotate"
agents:
# requires at least "bash", "curl" and "git"
Expand Down
1 change: 1 addition & 0 deletions .buildkite/pull-requests.json
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@
"^.github/ISSUE_TEMPLATE/",
"^docs/",
"^catalog-info.yaml$",
"^CODE_OF_CONDUCT.md$",
"^.buildkite/pipeline.schedule-daily.yml$",
"^.buildkite/pipeline.schedule-weekly.yml$",
"^.buildkite/pipeline.backport.yml$",
Expand Down
3 changes: 3 additions & 0 deletions .buildkite/scripts/check_sources.sh
Original file line number Diff line number Diff line change
Expand Up @@ -7,10 +7,13 @@ set -euo pipefail
add_bin_path
with_mage

echo "--- Run mage check"
mage -v check

echo "--- Check if any files modified"
check_git_diff

echo "--- Run elastic-package links"
run_links_command=false
if less_than=$(mage isElasticPackageDependencyLessThan 0.113.0) ; then
# links command require at least v0.113.0
Expand Down
13 changes: 4 additions & 9 deletions .buildkite/scripts/common.sh
Original file line number Diff line number Diff line change
Expand Up @@ -125,14 +125,9 @@ with_mage() {
create_bin_folder
with_go

local install_packages=(
"github.com/magefile/mage"
"github.com/jstemmer/go-junit-report"
"gotest.tools/gotestsum"
)
for pkg in "${install_packages[@]}"; do
go install "${pkg}@latest"
done
# Install version from go.mod"
go install "github.com/magefile/mage"

mage --version
}

Expand Down Expand Up @@ -768,7 +763,7 @@ is_pr_affected() {
# Example:
# https://buildkite.com/elastic/integrations/builds/25606
# https://github.com/elastic/integrations/pull/13810
if git diff --name-only "${commit_merge}" "${to}" | grep -E -v '^(packages/|\.github/(CODEOWNERS|ISSUE_TEMPLATE|PULL_REQUEST_TEMPLATE|workflows/)|README\.md|docs/|catalog-info\.yaml|\.buildkite/(pull-requests\.json|pipeline\.schedule-daily\.yml|pipeline\.schedule-weekly\.yml|pipeline\.backport\.yml))' > /dev/null; then
if git diff --name-only "${commit_merge}" "${to}" | grep -E -v '^(packages/|\.github/(CODEOWNERS|ISSUE_TEMPLATE|PULL_REQUEST_TEMPLATE|workflows/)|CODE_OF_CONDUCT\.md|README\.md|docs/|catalog-info\.yaml|\.buildkite/(pull-requests\.json|pipeline\.schedule-daily\.yml|pipeline\.schedule-weekly\.yml|pipeline\.backport\.yml))' > /dev/null; then
echo "[${package}] PR is affected: found non-package files"
return 0
fi
Expand Down
42 changes: 0 additions & 42 deletions .buildkite/scripts/run_sonar_scanner.sh

This file was deleted.

Loading
Loading