Skip to content

[Network Beaconing Identification] Add process related fields to beaconing transform - #18748

Merged
sodhikirti07 merged 6 commits into
mainfrom
update-beaconing-transform-fields
May 5, 2026
Merged

sodhikirti07 merged 6 commits into
mainfrom
update-beaconing-transform-fields

Conversation

@sodhikirti07

Copy link
Copy Markdown
Contributor

Proposed commit message

Add process related fields to beaconing transform

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Author's Checklist

  • [ ]

How to test this PR locally

  • Tested using ITP

Related issues

Screenshots

Transform and detection alerts preview

image image

@sodhikirti07
sodhikirti07 requested a review from a team as a code owner April 30, 2026 16:39
@sodhikirti07 sodhikirti07 added the enhancement New feature or request label Apr 30, 2026
@sodhikirti07
sodhikirti07 requested a review from a team as a code owner April 30, 2026 16:39
@sodhikirti07 sodhikirti07 added the Integration:beaconing Network Beaconing Identification label Apr 30, 2026
Comment thread packages/beaconing/changelog.yml
@jmcarlock

Copy link
Copy Markdown
Contributor

Looks good. My suggestion is to make process.executable fallback to having an empty string like the other new fields to guarantee backward compatibility/use with other integrations. Otherwise it is required to run the transform.

'source.ip':
terms:
field: source.ip
'process.executable':

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High pivot_transform/transform.yml:353

The 12 new group_by fields added in this PR are not defined in fields.yml, so the destination index ml_beaconing-1.6.0 will use dynamic mapping. Since the Painless scripts convert process.pid and process.parent.pid to strings via .toString(), Elasticsearch may map these as text instead of keyword, breaking downstream queries and detection rules that expect consistent field types. Consider adding explicit field definitions to packages/beaconing/elasticsearch/transform/pivot_transform/fields/fields.yml.

🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file packages/beaconing/elasticsearch/transform/pivot_transform/transform.yml around line 353:

The 12 new `group_by` fields added in this PR are not defined in `fields.yml`, so the destination index `ml_beaconing-1.6.0` will use dynamic mapping. Since the Painless scripts convert `process.pid` and `process.parent.pid` to strings via `.toString()`, Elasticsearch may map these as `text` instead of `keyword`, breaking downstream queries and detection rules that expect consistent field types. Consider adding explicit field definitions to `packages/beaconing/elasticsearch/transform/pivot_transform/fields/fields.yml`.

@jmcarlock

Copy link
Copy Markdown
Contributor

LGTM! Agree with the macroscopeapp, the field definitions also need updating

@andrewkroh andrewkroh added the Team:Security-Applied ML Elastic Security Protections Machine Learning (ML) team [elastic/sec-applied-ml] label Apr 30, 2026
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/sec-applied-ml (Team:Security-Applied ML)

name: process.working_directory
- external: ecs
name: process.pid
- external: ecs

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Have you tested what the output of using the ECS fields results in?
As mentioned the transform tostring() may go to text or keyword
But does using external: ecs automatically then handle the process to store them in long?
Just to be sure how it actually works, and where that translation is being done

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you Susan for mentioning this. I've added a processor in the ingest pipeline that will correctly cast the process related 4 fields to correct ECS type.

@sodhikirti07
sodhikirti07 requested a review from jmcarlock May 1, 2026 19:21
@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

if (!v.isEmpty()) {
if (ctx.process == null) { ctx.process = new HashMap(); }
if (ctx.process.parent == null) { ctx.process.parent = new HashMap(); }
ctx.process.parent.pid = Long.parseLong(v);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there any possibility of ctx.process_parent_pid missing and how would that be handled?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These fields can be missing, and that is handled by the null and empty checks in the ingest pipeline. If the value is missing, the entire block (e.g. lines 26–33 for process.parent.pid) is skipped, so the field is never written to the output document, it is simply do not exist from the transform's output.

@andrewkroh andrewkroh removed the Integration:beaconing Network Beaconing Identification label May 4, 2026
@andrewkroh andrewkroh added the Integration:beaconing Network Beaconing Identification label May 4, 2026

@susan-shu-c susan-shu-c left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for addressing review/questions!

@sodhikirti07
sodhikirti07 merged commit 11e9bc9 into main May 5, 2026
12 checks passed
@sodhikirti07
sodhikirti07 deleted the update-beaconing-transform-fields branch May 5, 2026 13:14
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package beaconing - 1.6.0 containing this change is available at https://epr.elastic.co/package/beaconing/1.6.0/

herrBez pushed a commit to herrBez/integrations that referenced this pull request Jun 1, 2026
…oning transform (elastic#18748)

* Add process related fields to beaconing transform

* update transform

* update changelog.yml

* add fallback logic for process.executable

* update fields.yml and add _dev folder

* correctly cast the process related fields in ingest pipeline
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:beaconing Network Beaconing Identification Team:Security-Applied ML Elastic Security Protections Machine Learning (ML) team [elastic/sec-applied-ml]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants