Skip to content

[Zscaler Private Access] Skip IP convert when source fields are empty strings - #21865

Merged
marc-gr merged 2 commits into
elastic:mainfrom
moxarth-rathod:zscaler-zpa-sdh-fix
Oct 6, 2026
Merged

marc-gr merged 2 commits into
elastic:mainfrom
moxarth-rathod:zscaler-zpa-sdh-fix

Conversation

@moxarth-rathod

Copy link
Copy Markdown
Contributor

Proposed commit message

  zscaler_zpa: skip IP convert when source fields are empty strings

  ZPA logs sometimes include IP-related fields as empty strings (""). The ingest
  pipelines were still running `convert` with type `ip` on those values, which
  triggers conversion errors. Each affected `convert` now runs only when the
  corresponding JSON field is not empty, across the app_connector_status,
  browser_access, user_activity, and user_status data streams.

  Test samples are based on live-captured logs.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

@moxarth-rathod moxarth-rathod self-assigned this Oct 6, 2026
@moxarth-rathod moxarth-rathod added the Integration:zscaler_zpa Zscaler Private Access label Oct 6, 2026
@moxarth-rathod
moxarth-rathod requested review from a team as code owners October 6, 2026 06:37
@moxarth-rathod moxarth-rathod added bugfix Pull request that fixes a bug issue Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] labels Oct 6, 2026
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@vera-review-bot

Copy link
Copy Markdown

🟢 No issues across the latest commits 799eb94.

A new commit triggers another review — at most once every 15 minutes. I skip the PR while it's approved or has merge conflicts.

🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills

⚠️ Automated review — verify suggestions before applying.

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

Package zscaler_zpa 👍(0) 💚(1) 💔(4)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
audit 5780.35 4115.23 -1665.12 (-28.81%) 💔
browser_access 2066.12 1377.41 -688.71 (-33.33%) 💔
user_activity 3521.13 1818.18 -1702.95 (-48.36%) 💔
user_status 6944.44 5076.14 -1868.3 (-26.9%) 💔

To see the full report comment with /test benchmark fullreport

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

cc @moxarth-rathod

@brijesh-elastic brijesh-elastic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mergify

mergify Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Queued — the merge queue status continues in this comment ↓.

@mergify

mergify Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Merge Queue Status

  • 🟠 Waiting for queue conditions
  • ⏳ Enter queue
  • ⏳ Run checks
  • ⏳ Merge
Required conditions to enter a queue
  • -closed [📌 queue requirement]
  • -conflict [📌 queue requirement]
  • -draft [📌 queue requirement]
  • any of [📌 queue -> configuration change requirements]:
    • -mergify-configuration-changed
    • check-success = @mergify/Configuration changed
    • check-success = @mergify/Configuration has been deleted
  • any of [🔀 queue conditions]:
    • all of [📌 queue conditions of queue rule default]:
      • github-review-approved [🛡 GitHub branch protection]
      • github-review-approved [🛡 GitHub repository ruleset rule [org] Require a PR for Renovate]
      • github-review-approved [🛡 GitHub repository ruleset rule [org] Require a PR]
      • any of [🛡 GitHub branch protection]:
        • check-success = CLA
        • check-neutral = CLA
        • check-skipped = CLA
      • any of [🛡 GitHub branch protection]:
        • check-success = buildkite/integrations
        • check-neutral = buildkite/integrations
        • check-skipped = buildkite/integrations

@marc-gr
marc-gr merged commit 3443637 into elastic:main Oct 6, 2026
13 of 14 checks passed
@mergify

mergify Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

queue

☑️ The pull request has been merged manually

Details

The pull request has been merged manually at 3443637

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package zscaler_zpa - 1.24.1 containing this change is available at https://epr.elastic.co/package/zscaler_zpa/1.24.1/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue Integration:zscaler_zpa Zscaler Private Access Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants