New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Osquery_manager: Upgrade osquery_manager for serverless, pick up ECS 8.10.0 #7894
Conversation
hmmm, the error in CI
|
/test |
/test |
Please wait to merge this PR @aleksmaus , merging this branch would publish this package as GA with spec v3 but this spec is not GA yet. We are checking how this validation is performed in elastic-package to try avoid this situation. Thanks!! |
@aleksmaus you could proceed with this PR, just be aware that the spec v3 is not GA yet and there could be still changes in that version (e.g. more validation rules to be applied). Just as a note, remember to add the capabilities if this package has some special requirement. Sorry for the inconveniences! |
Thanks!
I tried to re-kick the PR build, didn't help |
mmm that kibana image was deleted, that's why the testing fails. This has already been applied in at least 3 packages: $ git grep "\^8.10.1" | grep manifest
awsfirehose/manifest.yml: kibana.version: "^8.10.1"
okta/manifest.yml: kibana.version: ^8.10.1
security_detection_engine/manifest.yml: kibana.version: ^8.10.1 |
….10.0 was deleted
🌐 Coverage report
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This looks good.
I saw a few more fields that could be changed over to use external: ecs
if you wanted.
packages/osquery_manager/data_stream/result/fields/base-fields.yml:1:3 data_stream.type
packages/osquery_manager/data_stream/result/fields/base-fields.yml:4:3 data_stream.dataset
packages/osquery_manager/data_stream/result/fields/base-fields.yml:7:3 data_stream.namespace
packages/osquery_manager/data_stream/result/fields/base-fields.yml:10:3 @timestamp
These two fields, title and description on a "group", can be removed. That are not used for anything in packages or Fleet (source). |
I tried to update to ^8.10.1 the build still fails in CI
|
/test |
That last failure was 18 hours ago which was during a docker hub outage. That might have been the cause. Retrying. |
Package osquery_manager - 1.10.0 containing this change is available at https://epr.elastic.co/search?package=osquery_manager |
What does this PR do?
Upgrades osquery_manager for serverless specs
Picks up ECS 8.10.0
Checklist
changelog.yml
file.Screenshots
Tested following the serverless opt-in packages guide.