-
Notifications
You must be signed in to change notification settings - Fork 407
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Suricata] Add Observer Metadata #6985
Conversation
…akoWish/integrations into suricata_add_observer_metadata
packages/suricata/data_stream/eve/_dev/test/pipeline/test-common-config.yml
Outdated
Show resolved
Hide resolved
packages/suricata/data_stream/eve/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
…akoWish/integrations into suricata_add_observer_metadata
packages/winlog/data_stream/winlog/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
…akoWish/integrations into suricata_add_observer_metadata
…akoWish/integrations into suricata_add_observer_metadata
…akoWish/integrations into suricata_add_observer_metadata
/test |
🌐 Coverage report
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
minor nit and then LGTM
packages/suricata/data_stream/eve/_dev/test/pipeline/test-eve-alerts.log-config.yml
Show resolved
Hide resolved
packages/suricata/data_stream/eve/_dev/test/pipeline/test-eve-small.log-config.yml
Show resolved
Hide resolved
…akoWish/integrations into suricata_add_observer_metadata
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
@efd6 , Would you mind kicking off a |
/test |
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as |
/test |
You'll need to run |
…akoWish/integrations into suricata_add_observer_metadata
I usually do, but looks like I didn't on this one. Done. |
/test |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks
Package suricata - 2.18.0 containing this change is available at https://epr.elastic.co/search?package=suricata |
Type of change
What does this PR do?
The Suricata integration currently supports removing
host.*
fields if "forwarded" is intags
, but it does not currently populate theobserver.*
fields. This PR adds that functionality.Checklist
changelog.yml
file.manifest.yml
file.Author's Checklist
observer.*
fieldsRelated issues
observer.*
Fields for Integration #6984