ti_abusech: Adjust field mappings for transform - #10049
Conversation
🚀 Benchmarks reportTo see the full report comment with |
d06d4b6 to
e1e7a64
Compare
💚 Build Succeeded
History
cc @kcreddy |
|
Attached are the mappings I tested for AbuseCH.
I verified source vs dest mappings for same version (8.13 and 8.14). I also verified dest 8.13 vs dest 8.14 mappings. All of them correctly match, except for Malware datastream. All of destination mappings are adding the missing fields |
|
Added few more |
That reproduces for me. I see the malwarebazaar fields in the The extra mappings won't break anything in this use-case, will they? |
Yeah, they shouldn't be a problem.
Created: elastic/kibana#184759 |
|
Package ti_abusech - 2.0.1 containing this change is available at https://epr.elastic.co/search?package=ti_abusech |
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |





Proposed commit message
Checklist
changelog.ymlfile.Author's Checklist
event.module,event.dataset,threat.feed.name, andthreat.feed.dashboard_idRelated issues