Skip to content

[Security Solution] ECS 1.11 Signal Mappings#108764

Merged
rylnd merged 2 commits intoelastic:masterfrom
rylnd:secsol_ecs_1.11
Aug 17, 2021
Merged

[Security Solution] ECS 1.11 Signal Mappings#108764
rylnd merged 2 commits intoelastic:masterfrom
rylnd:secsol_ecs_1.11

Conversation

@rylnd
Copy link
Copy Markdown
Contributor

@rylnd rylnd commented Aug 16, 2021

Summary

This is a release chore for 7.15.0: updating signals mappings with the latest supported ECS version.

For maintainers

* Ensures no constant_keyword mappings
* Bumps index version by 1, since it was already bumped by 10 for 7.15
  in elastic#106049
@rylnd rylnd added release_note:enhancement v8.0.0 Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v7.15.0 labels Aug 16, 2021
@rylnd rylnd self-assigned this Aug 16, 2021
@rylnd rylnd added the chore label Aug 16, 2021
Until the old, 7.14 enrichment mappings (which define threat.indicator
as nested) are in our rearview, we cannot add the official, non-nested
threat.indicator mappings as they'll conflict.
@kibanamachine
Copy link
Copy Markdown
Contributor

💚 Build Succeeded

Metrics [docs]

✅ unchanged

History

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

cc @rylnd

@rylnd rylnd marked this pull request as ready for review August 17, 2021 14:43
@rylnd rylnd requested a review from a team as a code owner August 17, 2021 14:43
@elasticmachine
Copy link
Copy Markdown
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

Copy link
Copy Markdown
Contributor

@FrankHassanabad FrankHassanabad left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM,

  • Looked over the code
  • Double checked that constant_keyword was not added.
  • Saw that the threat mappings were removed which I think this is what we want 👍

@rylnd rylnd added the auto-backport Deprecated - use backport:version if exact versions are needed label Aug 17, 2021
@rylnd rylnd merged commit d509884 into elastic:master Aug 17, 2021
@rylnd rylnd deleted the secsol_ecs_1.11 branch August 17, 2021 18:22
kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Aug 17, 2021
* Update signals mappings to include ECS 1.11

* Ensures no constant_keyword mappings
* Bumps index version by 1, since it was already bumped by 10 for 7.15
  in elastic#106049

* Remove threat.indicator mappings from signals indices

Until the old, 7.14 enrichment mappings (which define threat.indicator
as nested) are in our rearview, we cannot add the official, non-nested
threat.indicator mappings as they'll conflict.
@kibanamachine
Copy link
Copy Markdown
Contributor

💚 Backport successful

Status Branch Result
7.x

This backport PR will be merged automatically after passing CI.

kibanamachine added a commit that referenced this pull request Aug 17, 2021
* Update signals mappings to include ECS 1.11

* Ensures no constant_keyword mappings
* Bumps index version by 1, since it was already bumped by 10 for 7.15
  in #106049

* Remove threat.indicator mappings from signals indices

Until the old, 7.14 enrichment mappings (which define threat.indicator
as nested) are in our rearview, we cannot add the official, non-nested
threat.indicator mappings as they'll conflict.

Co-authored-by: Ryland Herrick <ryalnd@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-backport Deprecated - use backport:version if exact versions are needed chore release_note:enhancement Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v7.15.0 v8.0.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants