Skip to content

ti_misp: honor preserve_original_event tag - #5190

Merged
efd6 merged 1 commit into
elastic:mainfrom
efd6:5189-ti_misp
Feb 7, 2023
Merged

efd6 merged 1 commit into
elastic:mainfrom
efd6:5189-ti_misp

Conversation

@efd6

@efd6 efd6 commented Feb 7, 2023

Copy link
Copy Markdown
Contributor

What does this PR do?

Previously there was no remove processor that would delete event.original when preserve_original_event was not present. In addition to this, the tags field was clobbered by the misp.tag script processor, so be more careful with retaining existing tags. Also clean up some potential null deref issues.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Screenshots

@efd6 efd6 added bug Something isn't working, use only for issues Team:Security-External Integrations Integration:ti_misp MISP labels Feb 7, 2023
@efd6 efd6 self-assigned this Feb 7, 2023
@elasticmachine

elasticmachine commented Feb 7, 2023 •

Copy link
Copy Markdown

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2023-02-07T01:27:01.123+0000

  • Duration: 14 min 38 sec

Test stats 🧪

Test Results
Failed 0
Passed 10
Skipped 0
Total 10

🤖 GitHub comments

Expand to view the GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

Previously there was no remove processor that would delete event.original when
preserve_original_event was not present. In addition to this, the tags field was
clobbered by the misp.tag script processor, so be more careful with retaining
existing tags. Also clean up some potential null deref issues.
@elasticmachine

Copy link
Copy Markdown

🌐 Coverage report

Name Metrics % (covered/total) Diff
Packages 100.0% (1/1) 💚
Files 100.0% (1/1) 💚
Classes 100.0% (1/1) 💚
Methods 100.0% (14/14) 💚
Lines 88.704% (267/301) 👍 3.869
Conditionals 100.0% (0/0) 💚

@efd6
efd6 marked this pull request as ready for review February 7, 2023 02:16
@efd6
efd6 requested a review from a team as a code owner February 7, 2023 02:16
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@efd6
efd6 requested a review from P1llus February 7, 2023 02:17
@efd6
efd6 merged commit 366c93c into elastic:main Feb 7, 2023
@elasticmachine

Copy link
Copy Markdown

Package ti_misp - 1.10.0 containing this change is available at https://epr.elastic.co/search?package=ti_misp

@efd6
efd6 deleted the 5189-ti_misp branch February 5, 2025 22:11
orestisfl pushed a commit to orestisfl/integrations that referenced this pull request May 15, 2026
Previously there was no remove processor that would delete event.original when
preserve_original_event was not present. In addition to this, the tags field was
clobbered by the misp.tag script processor, so be more careful with retaining
existing tags. Also clean up some potential null deref issues.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working, use only for issues Integration:ti_misp MISP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ti_misp: does not honor preserve_original_event tag

3 participants