Repository navigation
Retain event.original value upon pipeline errors #12045
Copy link
Copy link
Closed
Enhancement
3 / 33 of 3 issues completed
Copy link
Labels
Integration:AllBulk changes that touch every integrationBulk changes that touch every integrationTeam:Security-Linux PlatformLinux Platform Security team [elastic/sec-linux-platform]Linux Platform Security team [elastic/sec-linux-platform]Team:Security-ScalabilitySecurity Integrations Scalability teamSecurity Integrations Scalability teamTeam:Security-Windows PlatformSecurity Windows Platform team [elastic/sec-windows-platform]Security Windows Platform team [elastic/sec-windows-platform]enhancementNew feature or requestNew feature or request
Description
Activity
- addedenhancementNew feature or requestNew feature or requestIntegration:AllBulk changes that touch every integrationBulk changes that touch every integrationTeam:Security-Deployment and DevicesDEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]Team:Security-Linux PlatformLinux Platform Security team [elastic/sec-linux-platform]Linux Platform Security team [elastic/sec-linux-platform]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Security-ScalabilitySecurity Integrations Scalability teamSecurity Integrations Scalability teamTeam:Security-Windows PlatformSecurity Windows Platform team [elastic/sec-windows-platform]Security Windows Platform team [elastic/sec-windows-platform]
on Dec 9, 2024 Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)
Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform)
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)
Pinging @elastic/security-scalability (Team:Security-Scalability)
Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)
- removedTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Security-Deployment and DevicesDEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]
on Sep 10, 2025 #12046 contains the script that was used to apply changes to the security service team integrations.
Reacted by Hanna Tamoudi
Metadata
Metadata
Assignees
Labels
Integration:AllBulk changes that touch every integrationBulk changes that touch every integrationTeam:Security-Linux PlatformLinux Platform Security team [elastic/sec-linux-platform]Linux Platform Security team [elastic/sec-linux-platform]Team:Security-ScalabilitySecurity Integrations Scalability teamSecurity Integrations Scalability teamTeam:Security-Windows PlatformSecurity Windows Platform team [elastic/sec-windows-platform]Security Windows Platform team [elastic/sec-windows-platform]enhancementNew feature or requestNew feature or request
When an ingest pipeline error occurs, our log pipelines should retain the
event.originalvalue to ensure that no data loss occurs and to facilitate correcting the failure. If processing is interrupted due to an error, some data may not have been extracted (i.e. incomplete processing) so it's important to retain theevent.original. And secondly, in order for the package maintainers to be able to take action on reports of pipeline failures they nearly always need theevent.originalvalue to reproduce and understand the issue.To implement this we should complete the work related to #10072. This not strictly required, but it helps ensure the
event.originalis consistently handled. We want the Fleet final_pipeline to be responsible for deleting event.original whentagsdoes not containpreserve_original_event.Next, in the primary pipeline of each log data stream we update the global
on_failurehandler to injectpreserve_original_eventintotags. This will accompanyevent.kind: pipeline_error. With this mechanism, users can still override this behavior through the various levels of@custompipelines by deleting the tag value. I expect the work to be accomplished "mechanically", and this mechanism can be applied separately on the integrations owned by each SIT team.TODO
preserve_original_eventin primary on_failure handlers