Initial structure#1
Conversation
Prelim for System Test-Microsoft_sql Server
|
Package ti_cif3 - 0.4.1 containing this change is available at https://epr.elastic.co/search?package=ti_cif3 |
|
Package ti_otx - 1.7.1 containing this change is available at https://epr.elastic.co/search?package=ti_otx |
|
Package ti_threatq - 1.8.1 containing this change is available at https://epr.elastic.co/search?package=ti_threatq |
|
Package okta - 1.15.1 containing this change is available at https://epr.elastic.co/search?package=okta |
|
Package redis - 1.9.1 containing this change is available at https://epr.elastic.co/search?package=redis |
|
Package windows - 1.22.0 containing this change is available at https://epr.elastic.co/search?package=windows |
|
Package hashicorp_vault - 1.13.0 containing this change is available at https://epr.elastic.co/search?package=hashicorp_vault |
|
Package o365 - 1.24.1 containing this change is available at https://epr.elastic.co/search?package=o365 |
|
Package nats - 1.3.3 containing this change is available at https://epr.elastic.co/search?package=nats |
* [activemq]: migration with yq * [airflow]: migration with yq * [apache]: migration with yq * [apache_spark]: migration with yq * [cassandra]: migration with yq * [cockroachdb]: migration with yq * [couchbase]: migration with yq * [couchdb]: migration with yq * [etcd]: migration with yq * [activemq] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 1.0.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/activemq * [apache_spark] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 1.0.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/apache_spark * [apache_tomcat] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 2.3.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/apache_tomcat * [cassandra] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 1.0.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/cassandra * [couchdb] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 1.0.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/couchdb * [airflow] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 1.0.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/airflow * [azure_functions] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 2.5.1 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/azure_functions * [ceph] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 2.0.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/ceph * [cockroachdb] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 1.0.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/cockroachdb * [coredns] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 2.0.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/coredns * [couchbase]: migration with yq * [couchbase] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 1.0.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/couchbase * [etcd] - removed dotted YAML keys from manifest The format_version in the package manifest changed from 1.0.0 to 3.0.0. Removed dotted YAML keys from package manifest. Added 'owner.type: elastic' to package manifest. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@latest -v -format-version=3.0.0 -skip-format -fix-dotted-yaml-keys -add-owner-type packages/etcd * Add validation.yml * Set correct PR number in changelog * Revert "[apache]: migration with yq" This reverts commit 1ea1e883119b54df303d4fc14c9bf4e2e270d32d. * [apache_spark]: normalize fields * [cassandra]: normalize fields * [apache_spark]: fix formatting to make ci happy * [cassandra]: fix formatting to make ci happy * Format packages and quote fields where necessary * [couchbase]: s/metrics_type/metric_type * [airflow]: remove duplicates from agent.yml instead of ecs.yml * [cockroachdb]: remove duplicates from agent.yml instead of ecs.yml * revert changes for packages for which v3 migration failed * Format packages and quote fields where necessary * Fix inconsistency w/ elastic-build * quote fields where necessary * Move container.labels to ecs.yml * Change type from object to unsinged_long * [ceph]: Explicit mapping for state.count and state.state_name * [apache_spark]: migration with yq * [apache_spark]: pass elastic-packge test static * [apache_spark]: format * [apache_spark]: format * Make event.type's value formatting consistent * Change type from nested to group * Change type from unsigned_long to long * Quote index.mapping.dimension_fields.limit to avoid getting changed by ep format * Revert "Quote index.mapping.dimension_fields.limit to avoid getting changed by ep format" This reverts commit 5ca725b.
|
Package sample - 999.999.999-beta-1699365663480 containing this change is available at https://epr.elastic.co/search?package=sample |
|
Package crowdstrike - 1.28.3 containing this change is available at https://epr.elastic.co/search?package=crowdstrike |
|
Package ti_crowdstrike - 0.3.0 containing this change is available at https://epr.elastic.co/search?package=ti_crowdstrike |
|
Package ti_threatconnect - 0.4.0 containing this change is available at https://epr.elastic.co/search?package=ti_threatconnect |
|
Package mysql - 1.24.0 containing this change is available at https://epr.elastic.co/search?package=mysql |
|
Package qualys_vmdr - 6.2.1 containing this change is available at https://epr.elastic.co/package/qualys_vmdr/6.2.1/ |
|
Package o365 - 2.31.0 containing this change is available at https://epr.elastic.co/package/o365/2.31.0/ |
Use codegen for the pipeline. While doing this remove duplicated
processors and group processors somewhat more logically.
[git-generate]
SHA=54781ceda31cbf6b74a434549c6eeb1652e0065c
git clone --depth=1 git@github.com:efd6/fdr_gen.git
(
cd fdr_gen
git fetch --depth=1 origin ${SHA}
INGEST=../packages/crowdstrike/data_stream/fdr/elasticsearch/ingest_pipeline
go run ./default.go -out ${INGEST}/default.yml
go run ./categorize.go -out ${INGEST}/categorize.yml
go run ./data_protection.go -out ${INGEST}/data_protection_detection_summary.yml
go run ./network.go -dir inbound -out ${INGEST}/inbound_network.yml
go run ./network.go -dir outbound -out ${INGEST}/outbound_network.yml
)
rm -rf fdr_gen
cd packages/crowdstrike
elastic-package changelog add --description "Improve ingest pipeline maintainability." --type enhancement --next minor --link elastic#1
Just adding placeholders for the initial folders.