-
Notifications
You must be signed in to change notification settings - Fork 407
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[O365] Add fingerprint processor to prevent ingestion of duplicate events #5047
[O365] Add fingerprint processor to prevent ingestion of duplicate events #5047
Conversation
…gested - Added a fingerprint processor to prevent duplicate events from being ingested. It generates a hash based on the o365audit field.
🌐 Coverage report
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
@@ -14,6 +14,11 @@ processors: | |||
- append: | |||
field: event.category | |||
value: web | |||
- fingerprint: | |||
fields: | |||
- o365audit |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This could potentially be o365audit.ObjectId
or o365audit.Id
for a cheaper fingerprint. (The latter matches the @metadata._id
that I see in logs).
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good point. For performance reasons, I think I'll go ahead and switch it to that.
Package o365 - 1.10.1 containing this change is available at https://epr.elastic.co/search?package=o365 |
What does this PR do?
Checklist
changelog.yml
file.Related issues