From a3cb9af02da312773efa4dd41f96a95645137a8d Mon Sep 17 00:00:00 2001 From: Chris Berkhout Date: Wed, 24 Jan 2024 16:42:51 +0100 Subject: [PATCH 1/3] Add threat.indicator.email.subject to latest_ioc transform destination. --- .../ti_misp/elasticsearch/transform/latest_ioc/fields/ecs.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/packages/ti_misp/elasticsearch/transform/latest_ioc/fields/ecs.yml b/packages/ti_misp/elasticsearch/transform/latest_ioc/fields/ecs.yml index 4719c670656..a9f7e59c644 100644 --- a/packages/ti_misp/elasticsearch/transform/latest_ioc/fields/ecs.yml +++ b/packages/ti_misp/elasticsearch/transform/latest_ioc/fields/ecs.yml @@ -78,3 +78,5 @@ name: organization.id - external: ecs name: labels +- name: threat.indicator.email.subject + type: keyword From 19d814bf6e7367afa5f16bc66f9a4cc421ed3c7a Mon Sep 17 00:00:00 2001 From: Chris Berkhout Date: Wed, 24 Jan 2024 16:49:04 +0100 Subject: [PATCH 2/3] Bump fleet transform version. --- .../ti_misp/elasticsearch/transform/latest_ioc/transform.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packages/ti_misp/elasticsearch/transform/latest_ioc/transform.yml b/packages/ti_misp/elasticsearch/transform/latest_ioc/transform.yml index e4ca3cf9cfb..545593ee0b4 100644 --- a/packages/ti_misp/elasticsearch/transform/latest_ioc/transform.yml +++ b/packages/ti_misp/elasticsearch/transform/latest_ioc/transform.yml @@ -33,4 +33,4 @@ retention_policy: _meta: managed: true # Bump this version to delete, reinstall, and restart the transform during package. - fleet_transform_version: 0.1.0 + fleet_transform_version: 0.1.1 From 7822d83f93d574630357afbbcea9813ac368ce6d Mon Sep 17 00:00:00 2001 From: Chris Berkhout Date: Wed, 24 Jan 2024 16:53:53 +0100 Subject: [PATCH 3/3] Update changelog and manifest. --- packages/ti_misp/changelog.yml | 5 +++++ packages/ti_misp/manifest.yml | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/packages/ti_misp/changelog.yml b/packages/ti_misp/changelog.yml index d0ef6fc71f8..54e883d5550 100644 --- a/packages/ti_misp/changelog.yml +++ b/packages/ti_misp/changelog.yml @@ -1,4 +1,9 @@ # newer versions go on top +- version: "1.30.1" + changes: + - description: Add recent new field to latest_ioc transform dest + type: enhancement + link: https://github.com/elastic/integrations/pull/8963 - version: "1.30.0" changes: - description: Added attribute limit option to the UI diff --git a/packages/ti_misp/manifest.yml b/packages/ti_misp/manifest.yml index 2d2725f1f76..f5f192f0a07 100644 --- a/packages/ti_misp/manifest.yml +++ b/packages/ti_misp/manifest.yml @@ -1,6 +1,6 @@ name: ti_misp title: MISP -version: "1.30.0" +version: "1.30.1" description: Ingest threat intelligence indicators from MISP platform with Elastic Agent. type: integration format_version: "3.0.0"