Repository navigation
[Fortinet Fortigate] Prevent pipeline failures from oversized duration and non-IP address values - #19893
Conversation
…d drop non-IP values from and
|
Pinging @elastic/integration-experience (Team:Integration-Experience) |
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
|
👀 I have started reviewing the PR |
|
👀 I have started reviewing the PR |
Vera Review BotFor the current commit state, I did not find any issues. 🤖 AI-Generated Review | Vera Review Bot | 📚 Knowledge base: integration-skills
|
🚀 Benchmarks reportTo see the full report comment with |
| target_field: network.direction | ||
| ignore_missing: true | ||
| if: ctx.network?.direction == null | ||
| - grok: |
There was a problem hiding this comment.
You should use a convert processor with type: ip to validate fields are IP addresses and will index in elasticsearch. The processor doesn't actually convert the field value or type (it's still a string), but you can attach an on_failure to remove invalid IPs.
TL;DRBuildkite failed during the pipeline upload because the PR can no longer be auto-merged with Remediation
Investigation detailsRoot CauseBuildkite's repository Current # newer versions go on top
- version: "1.36.7"
changes:
- description: Support plain word identifiers in login source field, such as FortiClient Flexible Communication (fgfm_fgc).
type: enhancement
link: https://github.com/elastic/integrations/pull/19935This PR adds a different Evidence
VerificationNot run: the failure occurs before Buildkite uploads/generated package test steps, so there are no package test logs for this build. What is this? | From workflow: PR Buildkite Detective Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not. |
# Conflicts: # packages/fortinet_fortigate/changelog.yml
|
✅ All changelog entries have the correct PR link. |
| <185>date=2026-03-31 time=07:48:26 devname="MYDEV" devid="MYDEVID" eventtime=1773733509096718719 tz="-0500" logid="0419016384" type="utm" subtype="ips" eventtype="signature" level="alert" vd="root" severity="high" srcip=10.11.12.1 dstip=10.7.1.5 srcintf="eth0" srcintfrole="undefined" dstintf="eth1" dstintfrole="undefined" sessionid=1234567 action="detected" proto=6 service="HTTP" vrf=2 policyid=11 poluuid="07689140-fad1-4833-93ff-a5fcfbdc3041" policytype="policy" attack="HTTP.X-Forwarded-For.Header.XSS" srcport=50123 dstport=443 hostname="10.5.0.1" url="/?sample=1" agent="curl/7.47.0" httpmethod="GET" direction="outgoing" attackid=55823 profile="Profile1" ref="http://www.fortinet.com/ids/VID55823" incidentserialno=12345678 msg="web_misc: HTTP.X-Forwarded-For.Header.XSS" forwardedfor="abcd0e.xff\"></script><script>alert(document.domain);</script>" crscore=30 craction=8192 crlevel="high" | ||
| <185>date=2026-03-31 time=07:48:26 devname="MYDEV" devid="MYDEVID" eventtime=1773733509096718719 tz="-0500" logid="0419016384" type="utm" subtype="ips" eventtype="signature" level="alert" vd="root" severity="high" srcip=10.11.12.1 dstip=10.7.1.5 srcintf="eth0" srcintfrole="undefined" dstintf="eth1" dstintfrole="undefined" sessionid=1234567 action="detected" proto=6 service="HTTP" vrf=2 policyid=11 poluuid="07689140-fad1-4833-93ff-a5fcfbdc3041" policytype="policy" attack="HTTP.X-Forwarded-For.Header.XSS" srcport=50123 dstport=443 hostname="10.5.0.1" url="/?sample=1" agent="curl/7.47.0" httpmethod="GET" direction="outgoing" attackid=55823 profile="Profile1" ref="http://www.fortinet.com/ids/VID55823" incidentserialno=12345678 msg="web_misc: HTTP.X-Forwarded-For.Header.XSS\\" forwardedfor="abcd0e.xff\"></script><script>alert(document.domain);</script>" crscore=30 craction=8192 crlevel="high" | ||
| <189>date=2026-06-25 time=17:42:42 devname="MYDEV" devid="MYDEVID" eventtime=1782409391234567890 tz="+0000" logid="0419016384" type="event" subtype="vpn" level="notice" vd="root" logdesc="IPsec tunnel statistics" msg="IPsec tunnel statistics" action="tunnel-stats" remip=192.0.2.10 locip=192.0.2.20 remport=500 locport=500 outintf="wan1" srccountry="Reserved" cookies="1111111122222222/3333333344444444" user="192.0.2.10" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="VPNTUNNEL" tunnelip=N/A tunnelid=1234567890 tunneltype="ipsec" duration=18446711111123456789 sentbyte=0 rcvdbyte=0 nextstat=600 fctuid="N/A" advpnsc=0 | ||
| <189>date=2026-06-25 time=13:43:13 devname="MYDEV" devid="MYDEVID" eventtime=1782409391234567890 tz="-0400" logid="0419016384" type="event" subtype="user" level="notice" vd="root" logdesc="Explicit proxy authentication successful" srcip=192.0.2.202 dstip=authid="AUTH-ID" user="user1" authproto="HTTP(192.0.2.202)" action="NEGO-auth" status="success" reason="Authentication succeeded" msg="User user1 succeeded in authentication" |
There was a problem hiding this comment.
Severity: 🔵 Low confidence: medium path: packages/fortinet_fortigate/data_stream/log/_dev/test/pipeline/test-fortinet-fix.log:23
The new test fixtures exercise the destination.ip drop path but not the symmetric source.ip drop path; add a log line with a non-IP srcip so remove_source_ip_a34d8ade is covered.
Details
This PR adds two symmetric convert-then-remove branches: convert_source_ip_d1d4ef25 (on_failure remove_source_ip_a34d8ade) and convert_destination_ip_3561ff45 (on_failure remove_destination_ip_4e25a91b). The added auth event line has a malformed dstip (dstip=authid="AUTH-ID"), so it exercises and verifies the destination.ip removal branch. No added fixture line contains a non-IP srcip, so the source.ip removal branch has no test coverage and a regression in that path would not be caught.
Recommendation:
Add a fixture line whose srcip is a non-IP value (mirroring the malformed dstip case) so the source.ip convert failure and removal are exercised, e.g.:
<189>date=2026-06-25 time=13:44:00 devname="MYDEV" devid="MYDEVID" eventtime=1782409391234567890 tz="-0400" logid="0419016384" type="event" subtype="user" level="notice" vd="root" logdesc="Explicit proxy authentication successful" srcip=notanip dstip=192.0.2.50 user="user2" action="NEGO-auth" status="success" reason="Authentication succeeded" msg="User user2 succeeded in authentication"
and add the matching entry to test-fortinet-fix.log-expected.json (regenerated via elastic-package test pipeline -g) confirming source.ip is absent.
🤖 AI-Generated Review | Vera Review Bot | 📚 Knowledge base: integration-skills
⚠️ Automated review — verify suggestions before applying.
Review summaryIssues found across the latest commits 02664d3…fde90d3 (43 commits) — 1 low
🤖 AI-Generated Review | Vera Review Bot | 📚 Knowledge base: integration-skills
|
💚 Build Succeeded
History
|
|
Tick the box to add this pull request to the merge queue (same as
|
|
Package fortinet_fortigate - 1.36.8 containing this change is available at https://epr.elastic.co/package/fortinet_fortigate/1.36.8/ |
Two FortiGate log conditions currently fail the whole document in the
logdata stream:durationoverflow — some FortiOS IPsectunnel-statsevents emit an unsigned 64-bitduration(e.g.18446744073700579894) that exceedslong, so the duration script throws and the entire event (incl.advpnsc, byte counts, etc.) is dropped.source.ip/destination.ip— malformed values (e.g.dstip=authid="...") causenetwork_direction/geoipto hard-fail and the field to be_ignoredat index time.Proposed commit message
Prevent pipeline failures from oversized duration and non-IP address values
Checklist
- [ ] I have verified that all data streams collect metrics or logs.changelog.ymlfile.- [ ] I have verified that Kibana version constraints are current according to guidelines.- [ ] I have verified that any added dashboard complies with Kibana's Dashboard good practicesRelated issues
Partially Resolves: #19832
Screenshots