New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Carbon Black Cloud] - Fix @timestamp value by changing source to device_timestamp #9380
Conversation
…tation for making integration GA
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
🚀 Benchmarks reportTo see the full report comment with |
💚 Build Succeeded
cc @ShourieG |
Quality Gate passedKudos, no new issues were introduced! 0 New issues |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Package carbon_black_cloud - 1.21.2 containing this change is available at https://epr.elastic.co/search?package=carbon_black_cloud |
Type of change
Proposed commit message
Till now the @timestamp value was created with the create_time value. But after some discussions internally it was found that this was incorrect as this is the time at which the event gets ingested into carbon black cloud. The correct source for the timestamp value is device_timestamp which is the time at which the event is detected by the device and reported. Changes have made to reflect this, and at the same time a new field has been introduced called create_time which mirrors the original create_time value so that data integrity is maintained with the original event.
NOTE
Please ignore the older commit history, as the branch was already existing locally without any changes from before but had merge commits as a result of merging upstream/main multiple times. Only the last few commits matter.
Checklist
changelog.yml
file.Author's Checklist
How to test this PR locally
Related issues
Screenshots
Test Results