[beyondtrust_isi] Initial release of BeyondTrust ISI#19152
[beyondtrust_isi] Initial release of BeyondTrust ISI#19152janvi-elastic wants to merge 3 commits into
Conversation
…18682) The initial release includes incident data stream, associated dashboards and visualizations. BeyondTrust ISI fields are mapped to their corresponding ECS fields where possible. Test samples were derived from documentation.
The initial release includes event data stream, associated dashboards and visualizations.
TL;DRBuildkite failed before tests because the PR merge simulation could not merge Remediation
Investigation detailsRoot CauseBuildkite's post-checkout hook performs an explicit merge of
PR changes include a
That overlaps with upstream changes in the same file region and triggers the merge conflict in CI. Evidence
Verification
Follow-upAfter resolving What is this? | From workflow: PR Buildkite Detective Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not. |
…OWNERS (#19157) Update changelog, version in manifest for BeyondTrust ISI and sync CODEOWNERS.
|
/test |
💔 Build Failed
Failed CI StepsHistory
|
Proposed commit message
The initial release includes Incident and Event data stream and associated dashboard.
BeyondTrust ISI fields are mapped to their corresponding ECS fields where possible.
Test samples were derived from documentation, which were subsequently
sanitized.
Checklist
How to test this PR locally
To test the beyondtrust_isi package:
Screenshots
Note: We don't have live instance. So we have created dashboard based on documentation. And the fields in dashboard used have field type in suffix. This integration follows a phased development process where individual data streams were reviewed and merged into a feature branch through separate PRs:
All PR's have been reviewed and merged in this feature branch, which is now ready for integration into the main branch.