Repository navigation
[abnormal_security] Initial release of the Abnormal Security - #10653
Conversation
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
🚀 Benchmarks reportTo see the full report comment with |
| "https://example.com", | ||
| "https://example.com", | ||
| "https://example.com", | ||
| "https://example.com", | ||
| "https://example.com" |
There was a problem hiding this comment.
I'm guessing that these would not all be duplicates in real data. Is that correct?
There was a problem hiding this comment.
Yes, it will be unique in real data.
There was a problem hiding this comment.
I don't think this should be an array. https://www.elastic.co/guide/en/ecs/current/ecs-url.html#field-url-original.
Better not copy array urls into url.original
| "https://example.com", | ||
| "https://example.com", | ||
| "https://example.com", | ||
| "https://example.com", | ||
| "https://example.com" |
There was a problem hiding this comment.
I don't think this should be an array. https://www.elastic.co/guide/en/ecs/current/ecs-url.html#field-url-original.
Better not copy array urls into url.original
| "abnormal_security-audit" | ||
| ], | ||
| "url": { | ||
| "extension": "1/messages/email_content/", |
There was a problem hiding this comment.
Can you apply similar change to this one: #9623 for all datastream's pipeline test config which use uri_parts?
The pipeline test config temporarily fixes issue with url.extension having flaky tests in versions 8.14+.
efd6
left a comment
There was a problem hiding this comment.
There is one outstanding issue.
| "code": string(resp.StatusCode), | ||
| "id": string(resp.Status), | ||
| "message": "GET:"+( | ||
| size(resp.Body) != 0 ? | ||
| string(resp.Body) | ||
| : | ||
| string(resp.Status) + ' (' + string(resp.StatusCode) + ')' | ||
| ), |
|
💚 Build Succeeded
History
|
|
Package abnormal_security - 0.1.0 containing this change is available at https://epr.elastic.co/search?package=abnormal_security |
…#10653) * Added ai_security_mailbox, audit, case and threat data stream. * Added data collection logic for all the data stream. * Added the ingest pipeline for all the data stream. * Mapped fields according to the ECS schema and added Fields metadata in the appropriate yml files. * Added dashboards and visualizations. * Added test for pipeline for all the data stream. * Added system test cases for all the data stream.
…#10653) * Added ai_security_mailbox, audit, case and threat data stream. * Added data collection logic for all the data stream. * Added the ingest pipeline for all the data stream. * Mapped fields according to the ECS schema and added Fields metadata in the appropriate yml files. * Added dashboards and visualizations. * Added test for pipeline for all the data stream. * Added system test cases for all the data stream.
Proposed commit message
Create New integration package abnormal_security.
Checklist
changelog.ymlfile.How to test this PR locally
Related issues
Screenshots