New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Azure] Add Microsoft Graph Activity Logs datastream #9314
Conversation
🚀 Benchmarks reportTo see the full report comment with |
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
fyi @aarju - any feedback you have around dashboards, docs, mappings, etc very welcome :) |
@jamiehynds I don't have any feedback at this time, but I'm looking forward to testing out this integration and I may have some feedback after using it with some live data. |
packages/azure/data_stream/graphactivitylogs/agent/stream/azure-eventhub.yml.hbs
Outdated
Show resolved
Hide resolved
packages/azure/data_stream/graphactivitylogs/agent/stream/azure-eventhub.yml.hbs
Outdated
Show resolved
Hide resolved
packages/azure/data_stream/graphactivitylogs/agent/stream/azure-eventhub.yml.hbs
Outdated
Show resolved
Hide resolved
packages/azure/data_stream/graphactivitylogs/agent/stream/log.yml.hbs
Outdated
Show resolved
Hide resolved
.../azure/data_stream/graphactivitylogs/elasticsearch/ingest_pipeline/azure-shared-pipeline.yml
Outdated
Show resolved
Hide resolved
packages/azure/data_stream/graphactivitylogs/elasticsearch/ingest_pipeline/default.yml
Show resolved
Hide resolved
source: ctx.message = ctx.message.replace(params.empty_field_name, '') | ||
params: | ||
empty_field_name: '"":"",' | ||
ignore_failure: true | ||
tag: script-message-emptyfields |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is a surprising order of fields.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It is. I took a base ingest pipeline template and modified for this usecase.
This processor is present in most of the package's datastreams. I wonder if its even required here. Might as well remove it.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Removed this processor in the new commit.
packages/azure/data_stream/graphactivitylogs/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/azure/data_stream/graphactivitylogs/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
💚 Build Succeeded
History
cc @kcreddy |
Quality Gate passedKudos, no new issues were introduced! 0 New issues |
Package azure - 1.10.0 containing this change is available at https://epr.elastic.co/search?package=azure |
@aarju This feature is now available. Please feel free to test and provide feedback. Thanks 😄 |
Proposed commit message
Checklist
changelog.yml
file.How to test this PR locally
elastic-package build && elastic-package stack up -d -v && eval "$(elastic-package stack shellinit)" && elastic-package test pipeline --generate -v
Related issues
Screenshots