Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[osquery] Make event.original optional, bump ECS version and add custom processors #1139

Merged
merged 1 commit into from
Jun 17, 2021

Conversation

marc-gr
Copy link
Contributor

@marc-gr marc-gr commented Jun 17, 2021

What does this PR do?

  • Adds custom processors and tags
  • Makes event.original optional
  • Bump ecs to 1.10.0
  • Remove remaining edge processing

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
    - [ ] If I'm introducing a new feature, I have modified the Kibana version constraint in my package's manifest.yml file to point to the latest Elastic stack release (e.g. ^7.13.0).

Related issues

Screenshots

image

@elasticmachine
Copy link

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@marc-gr marc-gr force-pushed the osquery-improvements branch from d21c1be to b04986a Compare June 17, 2021 09:37
@elasticmachine
Copy link

elasticmachine commented Jun 17, 2021

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview

Expand to view the summary

Build stats

  • Build Cause: Pull request #1139 updated

  • Start Time: 2021-06-17T09:51:58.478+0000

  • Duration: 17 min 0 sec

  • Commit: a474717

Test stats 🧪

Test Results
Failed 0
Passed 19
Skipped 0
Total 19

Trends 🧪

Image of Build Times

Image of Tests

Copy link
Member

@P1llus P1llus left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, though added a comment

packages/osquery/manifest.yml Show resolved Hide resolved
@marc-gr marc-gr force-pushed the osquery-improvements branch 4 times, most recently from a4d029b to 36a7ea0 Compare June 17, 2021 09:48
@marc-gr marc-gr force-pushed the osquery-improvements branch from 36a7ea0 to a474717 Compare June 17, 2021 09:51
@marc-gr marc-gr merged commit b59c156 into elastic:master Jun 17, 2021
@marc-gr marc-gr deleted the osquery-improvements branch June 17, 2021 12:52
eyalkraft pushed a commit to build-security/integrations that referenced this pull request Mar 30, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants