-
Notifications
You must be signed in to change notification settings - Fork 429
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[microsoft_dhcp] Add DHCPv6 support #2473
Conversation
- Add support for ingesting logs from Microsoft DHCPv6 Server - Split pipeline into DHCPv4 and DHCPv6 handlers, switches on filename - Filter out header lines using filebeat processor - Add observer metadata using filebeat processor - Add pipeline and system tests
💚 Build Succeeded
Expand to view the summary
Build stats
Test stats 🧪
🤖 GitHub commentsTo re-run your PR in the CI, just comment with:
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just a few minor comments.
packages/microsoft_dhcp/data_stream/log/elasticsearch/ingest_pipeline/default.yml
Show resolved
Hide resolved
packages/microsoft_dhcp/data_stream/log/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/microsoft_dhcp/data_stream/log/elasticsearch/ingest_pipeline/dhcp.yml
Show resolved
Hide resolved
packages/microsoft_dhcp/data_stream/log/elasticsearch/ingest_pipeline/dhcpv6.yml
Outdated
Show resolved
Hide resolved
packages/microsoft_dhcp/data_stream/log/elasticsearch/ingest_pipeline/dhcpv6.yml
Outdated
Show resolved
Hide resolved
… file - DHCP pipeline now uses similar method of assigning ECS fields like DHCPv6 - Added header lines to DHCP system test file - Switched event.action to string instead of array - Updated expected test result files
I also reworked the DHCP pipeline to use a similar method of setting ECS fields. It should be clearer now what event IDs are being enriched and it should also be easier moving forward to add more metadata as needed. One change I made was removing the |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
- Add support for ingesting logs from Microsoft DHCPv6 Server - Split pipeline into DHCPv4 and DHCPv6 handlers, switches on filename - Filter out header lines using filebeat processor - Add observer metadata using filebeat processor - Add pipeline and system tests - DHCP pipeline now uses similar method of assigning ECS fields like DHCPv6 - Added header lines to DHCP system test file
What does this PR do?
Checklist
changelog.yml
file.How to test this PR locally
Related issues