[Sophos] Update Sophos pipelines for new fields#2163
[Sophos] Update Sophos pipelines for new fields#2163andrewkroh merged 8 commits intoelastic:mainfrom
Conversation
b5aa4a8 to
df4a140
Compare
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
|
/test |
packages/sophos/data_stream/xg/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
|
Hey @legoguy1000 - can you advise on the current state of this PR? Do you need anything from us to move towards merging? |
I think the big thing was the question/conversation above regarding a couple of fields. |
|
Also i know this was also brought up in the Beats repo so we can also wait for that to be updated and then just copy the changes?? the parallel effort was also wonky as wanted to keep the changes consistent. |
|
I was just commenting about have parallel changes in elastic/beats#29002 (comment). |
|
Ok, I will rebase and get this updated. |
df4a140 to
bcb96c1
Compare
|
/test |
packages/sophos/data_stream/xg/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/sophos/data_stream/xg/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
andrewkroh
left a comment
There was a problem hiding this comment.
That link you referenced (https://docs.sophos.com/nsg/sophos-firewall/17.5/Help/en-us/webhelp/onlinehelp/nsg/sfos/concepts/LogFields.html) would be great to have in the documentation somewhere.
|
@andrewkroh pushed changes |
|
/test |
packages/sophos/data_stream/xg/elasticsearch/ingest_pipeline/firewall.yml
Outdated
Show resolved
Hide resolved
It has been ~6 months and the pipelien has been updated since.
|
/test |
|
some weird glitch with the pipeline. I tried to rebuild README and there are no changes so idk. |
You might have an old version of elastic-package. Try running |
What does this PR do?
Updates Sophos pipelines to support new fields.
Checklist
changelog.ymlfile.manifest.ymlfile to point to the latest Elastic stack release (e.g.^7.13.0).Author's Checklist
How to test this PR locally
Related issues
Screenshots