New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[TI_Anomali] Fix transform sort order field #7000
Conversation
💔 Tests Failed
Expand to view the summary
Build stats
Test stats 🧪
Test errorsExpand to view the tests failures
|
🌐 Coverage report
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
Where does the |
Hey @andrewkroh, Update: |
@andrewkroh, I made the I am using that calculated timestamp to populate |
Package ti_anomali - 1.14.1 containing this change is available at https://epr.elastic.co/search?package=ti_anomali |
* Change sort order field * for test * update pr num * remove default * change fleet version to upgrade the transform * add timestamp field * update pipeline tests
What does this PR do?
event.ingested
. Since this is not precise to the millisecond level, whenever events comes with both deleted and added for same indicator (within a second), the last activity is not preserved and the indicator is simply deleted.@timestamp
which has millisecond resolution, and thus preserves the correct order of events to store in the destination indices.Checklist
changelog.yml
file.Related issues