-
Notifications
You must be signed in to change notification settings - Fork 392
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
zscaler_zia: fix mapping of user identities #9041
Conversation
1244c69
to
bfbad75
Compare
🚀 Benchmarks reportTo see the full report comment with |
219ed16
to
7d5a2ba
Compare
7d5a2ba
to
645c3e8
Compare
💚 Build Succeeded
History
cc @efd6 |
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
field: related.user | ||
value: '{{{user.name}}}' | ||
allow_duplicates: false | ||
if: ctx.user?.name != null && !(ctx.user.name instanceof List) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If it's a list you could do foreach to append each one.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I actually had that code in, but never saw a case in any of the samples I could find. So I removed it. The type check here is fossilised paranoia.
@@ -1,7 +1,7 @@ | |||
{ | |||
"expected": [ | |||
{ | |||
"@timestamp": "2023-12-31T12:01:04.000Z", | |||
"@timestamp": "2024-12-31T12:01:04.000Z", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I didn't know about the yearless BSD syslog format until I saw this.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
One year should be enough for anyone.
Package zscaler_zia - 2.18.2 containing this change is available at https://epr.elastic.co/search?package=zscaler_zia |
Proposed commit message
See title.
Checklist
changelog.yml
file.Author's Checklist
How to test this PR locally
Related issues
Screenshots