-
Notifications
You must be signed in to change notification settings - Fork 392
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[suricata] Fix missing destination.ip #2564
Conversation
💚 Build Succeeded
Expand to view the summary
Build stats
Test stats 🧪
🤖 GitHub commentsTo re-run your PR in the CI, just comment with:
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Take the opportunity to normalise field order?
I must need to update my elastic-package. 💡 Will do that. |
* Regenerate pipeline test events * Remove event.ingested * Use allowed geoip test IPs in test logs * Use convert processor to set source/destination.ip * Format MAC addresses per RFC 7042 and ECS * Don't override event.{created,original} when reindexing * Use triple braces in templates or set.copy_from * Add changelog
What does this PR do?
Checklist
changelog.yml
file.Related issues