New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ti_maltiverse: move non-ECS fields out of root #7909
Conversation
4c635c5
to
d8136b2
Compare
9ccdbfa
to
9dcf850
Compare
🌐 Coverage report
|
9dcf850
to
a89d68d
Compare
The system tests failing for undefined fields was related to the fields.yml for the transform not being updated. System tests for transforms was added here: https://github.com/elastic/elastic-package/pull/1409/files |
a89d68d
to
9c701cc
Compare
type: long | ||
description: number of reports for the indicator | ||
- name: external_references | ||
type: flattened |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This must be flattened
because the transform imposes an index sort order and this is not compatible with nested
.
9c701cc
to
ba1e885
Compare
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
type: boolean | ||
description: boolean description tag | ||
- name: location | ||
type: boolean |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It looks like this field should be a geo_point
and maltiverse.location.{lat,lon}
should be removed.
The same applies to the transform fields.
type: text | ||
description: CIDR associated | ||
- name: city | ||
type: text |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
A lot these text
fields should be keyword
in my opinion. If they need to be searchable then we could add a multi-field as needed for text
or match_only_text
.
39e0911
to
90fa9ec
Compare
Package ti_maltiverse - 0.4.0 containing this change is available at https://epr.elastic.co/search?package=ti_maltiverse |
What does this PR do?
See title.
Checklist
changelog.yml
file.Author's Checklist
How to test this PR locally
Related issues
Screenshots