Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix zeek connection pipeline #22151

Merged
merged 1 commit into from
Oct 26, 2020

Conversation

leehinman
Copy link
Contributor

What does this PR do?

  • changes connection state for rejected from 'REG' to 'REJ'

https://docs.zeek.org/en/current/scripts/base/protocols/conn/main.zeek.html

Why is it important?

Rejected connection states weren't matching.

Checklist

- [ ] My code follows the style guidelines of this project
- [ ] I have commented my code, particularly in hard-to-understand areas
- [ ] I have made corresponding changes to the documentation
- [ ] I have made corresponding change to the default configuration files
- [ ] I have added tests that prove my fix is effective or that my feature works

  • I have added an entry in CHANGELOG.next.asciidoc or CHANGELOG-developer.next.asciidoc.

How to test this PR locally

TESTING_FILEBEAT_MODULES=zeek TESTING_FILEBEAT_FILESETS=connection mage -v pythonIntegTest

Related issues

@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Oct 26, 2020
@leehinman leehinman added bug Filebeat Filebeat needs_backport PR is waiting to be backported to other branches. Team:Security-External Integrations labels Oct 26, 2020
@elasticmachine
Copy link
Collaborator

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Oct 26, 2020
- connection state for rejected is 'REJ'

Closes elastic#22149
@leehinman leehinman force-pushed the 22149_zeek_conn_pipeline branch from 3449add to 15f1266 Compare October 26, 2020 14:31
@elasticmachine
Copy link
Collaborator

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview

Expand to view the summary

Build stats

  • Build Cause: [Pull request #22151 updated]

  • Start Time: 2020-10-26T14:32:16.582+0000

  • Duration: 62 min 57 sec

Test stats 🧪

Test Results
Failed 0
Passed 1947
Skipped 259
Total 2206

@leehinman leehinman merged commit 5469c46 into elastic:master Oct 26, 2020
@leehinman leehinman added v7.11.0 and removed needs_backport PR is waiting to be backported to other branches. labels Oct 26, 2020
leehinman added a commit to leehinman/beats that referenced this pull request Oct 26, 2020
- connection state for rejected is 'REJ'

Closes elastic#22149

(cherry picked from commit 5469c46)
leehinman added a commit to leehinman/beats that referenced this pull request Oct 26, 2020
- connection state for rejected is 'REJ'

Closes elastic#22149

(cherry picked from commit 5469c46)
v1v added a commit to v1v/beats that referenced this pull request Oct 26, 2020
…ter-commit

* upstream/master: (25 commits)
  [CI] set env variable for the params (elastic#22143)
  Fix zeek connection pipeline (elastic#22151)
  Fix Google Cloud Function configuration file issues (elastic#22156)
  Remove old TODO on kubernetes node update (elastic#22074)
  [CI] Enable winlogbeat (elastic#22142)
  [CI] support windows-10 (elastic#19804)
  Use default config when creating the input (elastic#22126)
  Change x509 mappings from file. to tls.server. (elastic#22097)
  Add fleet settings image (elastic#22065)
  Edit 7.9.3 changelog (elastic#22117)
  Edit 6.8.13 release notes (elastic#22120)
  Incorporate librpm fix feedback (elastic#22098)
  [libbeat] Add more disk queue unit tests and fix a size-check bug (elastic#22107)
  docs: move kerberos include (elastic#22109)
  Check context.Canceled and fix s3 input config (elastic#22036)
  Add max_number_of_messages into aws filebeat fileset vars (elastic#22057)
  Remove suricata.eve.timestamp alias (elastic#22095)
  [Ingest Manager] Use symlink path for reexecutions (elastic#21835)
  chore: use ubuntu 18 as linux agent (elastic#22084)
  docs: Prepare Changelog for 7.9.3 (elastic#22073) (elastic#22075)
  ...
v1v added a commit to v1v/beats that referenced this pull request Oct 27, 2020
…laky-test-analyser

* upstream/master:
  Add new licence status: expired (elastic#22180)
  [filebeat][okta] Make cursor optional for okta and update docs (elastic#22091)
  Add documentation of filestream input (elastic#21615)
  [Ingest Manager] Skip flaky gateway tests elastic#22177
  [CI] set env variable for the params (elastic#22143)
  Fix zeek connection pipeline (elastic#22151)
  Fix Google Cloud Function configuration file issues (elastic#22156)
  Remove old TODO on kubernetes node update (elastic#22074)
v1v added a commit to v1v/beats that referenced this pull request Oct 27, 2020
…laky-test-analyser

* upstream/master:
  Add new licence status: expired (elastic#22180)
  [filebeat][okta] Make cursor optional for okta and update docs (elastic#22091)
  Add documentation of filestream input (elastic#21615)
  [Ingest Manager] Skip flaky gateway tests elastic#22177
  [CI] set env variable for the params (elastic#22143)
  Fix zeek connection pipeline (elastic#22151)
  Fix Google Cloud Function configuration file issues (elastic#22156)
  Remove old TODO on kubernetes node update (elastic#22074)
leehinman added a commit that referenced this pull request Oct 27, 2020
- connection state for rejected is 'REJ'

Closes #22149

(cherry picked from commit 5469c46)
leehinman added a commit that referenced this pull request Oct 27, 2020
- connection state for rejected is 'REJ'

Closes #22149

(cherry picked from commit 5469c46)
@leehinman leehinman deleted the 22149_zeek_conn_pipeline branch May 14, 2021 14:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[Filebeat] Incorrect connection state in zeek connection pipeline
3 participants