Skip to content

[Enhancement] Add ".caseless" fields to MDE process events - #11020

Merged
w0rk3r merged 6 commits into
mainfrom
fr-mde-caseless
Oct 23, 2024
Merged

[Enhancement] Add ".caseless" fields to MDE process events#11020
w0rk3r merged 6 commits into
mainfrom
fr-mde-caseless

Conversation

@w0rk3r

@w0rk3r w0rk3r commented Sep 5, 2024

Copy link
Copy Markdown
Contributor

Proposed commit message

Add caseless fields to MDE process events.

Summary

Adds caseless versions of process.name and process.executable as done in #10533.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Author's Checklist

  • [ ]

Related issues

https://github.com/elastic/ia-trade-team/issues/407

@w0rk3r w0rk3r added enhancement New feature or request Integration:m365_defender Microsoft Defender XDR Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Sep 5, 2024
@w0rk3r
w0rk3r requested a review from kcreddy September 5, 2024 19:17
@w0rk3r w0rk3r self-assigned this Sep 5, 2024
@w0rk3r
w0rk3r requested a review from a team as a code owner September 5, 2024 19:17
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elasticmachine

Copy link
Copy Markdown

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@kcreddy kcreddy left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor suggestion. LGTM 👍🏼

Comment thread packages/m365_defender/changelog.yml Outdated
Comment thread packages/m365_defender/manifest.yml Outdated
w0rk3r and others added 2 commits September 6, 2024 07:44
Co-authored-by: Krishna Chaitanya Reddy Burri <krishnachaitanyareddy.burri@elastic.co>
Co-authored-by: Krishna Chaitanya Reddy Burri <krishnachaitanyareddy.burri@elastic.co>
@botelastic

botelastic Bot commented Oct 6, 2024

Copy link
Copy Markdown

Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1. Thank you for your contribution!

@botelastic botelastic Bot added the Stalled label Oct 6, 2024
@botelastic botelastic Bot removed the Stalled label Oct 23, 2024
@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @w0rk3r

@w0rk3r
w0rk3r merged commit 313b143 into main Oct 23, 2024
@w0rk3r
w0rk3r deleted the fr-mde-caseless branch October 23, 2024 20:24
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package m365_defender - 2.15.1 containing this change is available at https://epr.elastic.co/search?package=m365_defender

harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 4, 2025
…1020)

* [Enhancement] Add ".caseless" fields to MDE process events

* Update packages/m365_defender/changelog.yml

Co-authored-by: Krishna Chaitanya Reddy Burri <krishnachaitanyareddy.burri@elastic.co>

* Update packages/m365_defender/manifest.yml

Co-authored-by: Krishna Chaitanya Reddy Burri <krishnachaitanyareddy.burri@elastic.co>

* Update manifest.yml

---------

Co-authored-by: Krishna Chaitanya Reddy Burri <krishnachaitanyareddy.burri@elastic.co>
harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 5, 2025
…1020)

* [Enhancement] Add ".caseless" fields to MDE process events

* Update packages/m365_defender/changelog.yml

Co-authored-by: Krishna Chaitanya Reddy Burri <krishnachaitanyareddy.burri@elastic.co>

* Update packages/m365_defender/manifest.yml

Co-authored-by: Krishna Chaitanya Reddy Burri <krishnachaitanyareddy.burri@elastic.co>

* Update manifest.yml

---------

Co-authored-by: Krishna Chaitanya Reddy Burri <krishnachaitanyareddy.burri@elastic.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:m365_defender Microsoft Defender XDR Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants