Skip to content

[main][Automation] Update elastic/beats to 1e373792d53d - #1

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
update-beats-main
Open

[main][Automation] Update elastic/beats to 1e373792d53d#1
github-actions[bot] wants to merge 1 commit into
mainfrom
update-beats-main

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown

What

Update elastic/beats to the latest version on branch main.

Changeset

ninalee12 pushed a commit that referenced this pull request Jul 21, 2026
## Summary

Follow-up to InfoSec's review of elastic#6991. Adds the remaining EC2 and ELB
fields InfoSec needs to retire their custom AWS CLI scripts for the
FedRAMP
asset inventory. All new fields land in `entity.attributes.*` (non-ECS,
UpperCamelCase) — no ECS mapping change required.

Tracking: elastic/security-team#17750

## Changes

**EC2** (`entity.attributes`):
- `ImageId`, `Platform`, `VpcId`, `SubnetId`, `State`, `RoleArn`
- `Owner`, `CostCenter` — resolved case-insensitively from instance tags

**ELB v1 + v2** (`entity.attributes`):
- `LoadBalancerType` — v2 reports the real type; v1 reports `classic`
- `AccountID`
- `State` — v2 only (`State.Code`); classic ELB exposes no state field
- `IPAddresses` — NLB static IPs; ALB/classic are DNS-only (empty)
- `OwnerTag` — required adding `DescribeTags` to both ELB `Client`
  interfaces and providers (batched to the 20-item AWS limit)

## Notes
- No `elastic/integrations` change: `entity.attributes` is `flattened`,
so
  new keys need no mapping and there's no migration.
- No new asset classifications, so `ASSETS.md` is unchanged. Route53 and
  EKS (also requested in the review) are separate follow-up PRs.
- Mocks regenerated; unit tests cover EC2 attributes and the ELB
  Type/State/IPAddresses/OwnerTag flow end-to-end.

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant