Update elastic/security artifacts#675
Conversation
Trim unused files
Remove unparsable field from logs@default-pipeline.json
|
@achuguy Under |
|
Question: does that logic generating the dataset needs adjustment? |
For generating a dataset I'll take endpoint data from a cluster with real endpoints. There is room to adjust fields in the dataset depending on cardinality needed. |
@salvatore-campagna When I'm trying to run the security-track with track-param Create composable index template Error Is the |
If you look at the copies under based on |
|
Looks like |
gbanasiak
left a comment
There was a problem hiding this comment.
I gave it a first pass. I may report more once I run the new track definition against a vanilla 8.15.1 cluster. I've labelled the PR with backport-to-8.15 to trigger automatic backport once this one is merged.
elastic/security/templates/component/logs-endpoint.events.library@package.json
Outdated
Show resolved
Hide resolved
elastic/security/templates/component/logs-endpoint.events.file@package.json
Outdated
Show resolved
Hide resolved
elastic/security/templates/component/logs-endpoint.events.registry@package.json
Outdated
Show resolved
Hide resolved
elastic/security/templates/component/logs-endpoint.events.security@package.json
Outdated
Show resolved
Hide resolved
|
LGTM after applying changes commented by @gbanasiak |
…tracks into update_security_artifacts
We can't backport it to |
|
To be clear, this is not a 8.16 vs 8.15 thing. |
|
Now with |
Thi si because it is using a feature flag right? That at some point will be removed. |
|
Thanks @gbanasiak and @achuguy for fixing this! |
💔 All backports failed
Manual backportTo create the backport manually run: Questions ?Please refer to the Backport tool documentation and see the Github Action logs for details |
|
@achuguy Can I ask for a manual backport to |
|
@gbanasiak Yes, I'll work on the backport |
Update the artifacts, composable templates, component templates, pipelines, ilm, used in the
elastic/securitytrack to Elasticsearch 8.15.1. Also deleting unused artifacts from the repo.