Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[7.x](backport #26627) [Filebeat] Remove alias fields from Suricata and Traefik module mappings #26896

Merged
merged 1 commit into from
Jul 27, 2021

Conversation

mergify[bot]
Copy link
Contributor

@mergify mergify bot commented Jul 15, 2021

This is an automatic backport of pull request #26627 done by Mergify.


Mergify commands and options

More conditions and actions can be found in the documentation.

You can also trigger Mergify actions by commenting on this pull request:

  • @Mergifyio refresh will re-evaluate the rules
  • @Mergifyio rebase will rebase this PR on its base branch
  • @Mergifyio update will merge the base branch into this PR
  • @Mergifyio backport <destination> will backport this PR on <destination> branch

Additionally, on Mergify dashboard you can:

  • look at your merge queues
  • generate the Mergify configuration with the config editor.

Finally, you can contact us on https://mergify.io/

…ngs (#26627)

* Remove alias fields from Suricata/Traefik module mappings

Alias fields are displayed in Kibana whenever their target exists in a document. This yields
confusing results when, for example, you are looking at Zeek module events but see many
`suricata.eve.*` fields just because Zeek populates many ECS fields.

This is a breaking change for users that depend on the Suricata alias fields. Because these
alias cause issues for all users I think it best to remove them.

The following alias fields are removed:

suricata.eve.fileinfo.filename
suricata.eve.fileinfo.size
suricata.eve.dest_port
suricata.eve.src_port
suricata.eve.proto
suricata.eve.src_ip
suricata.eve.dest_ip
suricata.eve.http.status
suricata.eve.http.http_user_agent
suricata.eve.http.http_refer
suricata.eve.http.url
suricata.eve.http.hostname
suricata.eve.http.http_refer
suricata.eve.http.url
suricata.eve.http.hostname
suricata.eve.http.length
suricata.eve.http.http_method
suricata.eve.alert.severity
suricata.eve.alert.action
suricata.eve.flow.bytes_toclient
suricata.eve.flow.start
suricata.eve.flow.pkts_toclient
suricata.eve.flow.bytes_toserver
suricata.eve.flow.pkts_toserver
suricata.eve.app_proto
traefik.access.user_agent.device

Relates: #10535

* Fix changelog

(cherry picked from commit 877ae2c)
@mergify mergify bot added the backport label Jul 15, 2021
@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Jul 15, 2021
@botelastic
Copy link

botelastic bot commented Jul 15, 2021

This pull request doesn't have a Team:<team> label.

@elasticmachine
Copy link
Collaborator

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2021-07-15T04:07:31.004+0000

  • Duration: 97 min 30 sec

  • Commit: 3f755cf

Test stats 🧪

Test Results
Failed 0
Passed 14239
Skipped 2326
Total 16565

Trends 🧪

Image of Build Times

Image of Tests

💚 Flaky test report

Tests succeeded.

Expand to view the summary

Test stats 🧪

Test Results
Failed 0
Passed 14239
Skipped 2326
Total 16565

@andrewkroh andrewkroh merged commit 16108a6 into 7.x Jul 27, 2021
@mergify mergify bot deleted the mergify/bp/7.x/pr-26627 branch July 27, 2021 23:11
@mergify
Copy link
Contributor Author

mergify bot commented Oct 26, 2021

This pull request is now in conflicts. Could you fix it? 🙏
To fixup this pull request, you can check out it locally. See documentation: https://help.github.com/articles/checking-out-pull-requests-locally/

git fetch upstream
git checkout -b mergify/bp/7.x/pr-26627 upstream/mergify/bp/7.x/pr-26627
git merge upstream/7.x
git push upstream mergify/bp/7.x/pr-26627

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport needs_team Indicates that the issue/PR needs a Team:* label
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants