-
Notifications
You must be signed in to change notification settings - Fork 387
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
m*: ensure event.kind is correctly set for pipeline errors #6661
Conversation
m365_defender, mattermost, microsoft_defender_endpoint, microsoft_dhcp, microsoft_exchange_online_message_trace, mysql_enterprise
🌐 Coverage report
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Package m365_defender - 1.11.0 containing this change is available at https://epr.elastic.co/search?package=m365_defender |
Package mattermost - 1.10.0 containing this change is available at https://epr.elastic.co/search?package=mattermost |
Package microsoft_defender_endpoint - 2.13.0 containing this change is available at https://epr.elastic.co/search?package=microsoft_defender_endpoint |
Package microsoft_dhcp - 1.14.0 containing this change is available at https://epr.elastic.co/search?package=microsoft_dhcp |
Package microsoft_exchange_online_message_trace - 1.5.0 containing this change is available at https://epr.elastic.co/search?package=microsoft_exchange_online_message_trace |
Package mysql_enterprise - 1.7.0 containing this change is available at https://epr.elastic.co/search?package=mysql_enterprise |
What does this PR do?
Modify m365_defender, mattermost, microsoft_defender_endpoint, microsoft_dhcp, microsoft_exchange_online_message_trace and mysql_enterprise to correctly set
event.kind
for pipeline errors and ensureerror.message
is an array.modsecurity is omitted as there is a pending PR to fix ingest in that package.
Checklist
changelog.yml
file.Author's Checklist
How to test this PR locally
Related issues
Screenshots