[Zeek Radius] Add ECS compliance for event.outcome field in RADIUS data stream and add tunnel_client field support#17306
Conversation
…add tunnel_client field support
✅ Vale Linting ResultsNo issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
🚀 Benchmarks reportPackage
|
| Data stream | Previous EPS | New EPS | Diff (%) | Result |
|---|---|---|---|---|
known_services |
52631.58 | 43478.26 | -9153.32 (-17.39%) | 💔 |
pe |
30303.03 | 21276.6 | -9026.43 (-29.79%) | 💔 |
smb_mapping |
45454.55 | 38461.54 | -6993.01 (-15.38%) | 💔 |
dce_rpc |
18518.52 | 12195.12 | -6323.4 (-34.15%) | 💔 |
dhcp |
32258.06 | 20000 | -12258.06 (-38%) | 💔 |
dns |
30303.03 | 18867.92 | -11435.11 (-37.74%) | 💔 |
ftp |
41666.67 | 29411.76 | -12254.91 (-29.41%) | 💔 |
To see the full report comment with /test benchmark fullreport
|
Pinging @elastic/integration-experience (Team:Integration-Experience) |
|
@haetamoudi this looks ok - do you know if customers would build rules off of the existing wrong behaviour, where cc. @taylor-swanson just to get some eyes |
It probably will. For that reason, this should be a breaking change. |
Co-authored-by: Taylor Swanson <90622908+taylor-swanson@users.noreply.github.com>
Co-authored-by: Taylor Swanson <90622908+taylor-swanson@users.noreply.github.com>
Co-authored-by: Taylor Swanson <90622908+taylor-swanson@users.noreply.github.com>
taylor-swanson
left a comment
There was a problem hiding this comment.
LGTM
@qcorporation, @haetamoudi, does the breaking change committee need to be notified about this?
|
@taylor-swanson I did not know about the breaking change committee.. is there an official process defined somewhere? |
|
Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as |
|
@haetamoudi , if this has been approved by the breaking change committee, can we go ahead and merge this (after resolving the conflicts)? |
💚 Build Succeeded
History
|
|
Package zeek - 5.0.0 containing this change is available at https://epr.elastic.co/package/zeek/5.0.0/ |
Proposed commit message
Add ECS compliance for event.outcome field in RADIUS data stream and add tunnel_client field support
Zeek docs
Checklist
changelog.ymlfile.Related issues
Fixes https://github.com/elastic/enhancements/issues/26613
Screenshots