[ti_threatq] Map threat.indicator.provider from name instead of provider - #13137
Conversation
|
/test |
🚀 Benchmarks reportTo see the full report comment with |
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
| # newer versions go on top | ||
| - version: "1.33.0" | ||
| changes: | ||
| - description: Map threat.indicator.provider from name instead of provider. |
There was a problem hiding this comment.
| - description: Map threat.indicator.provider from name instead of provider. | |
| - description: Map threat.indicator.provider from `sources.name` instead of `sources.provider`. |
There was a problem hiding this comment.
Also `threat.indicator.provider` since the other fields are being rendered in <pre>.
efd6
left a comment
There was a problem hiding this comment.
Please expand the proposed commit message to explain why this is being done.
| # newer versions go on top | ||
| - version: "1.33.0" | ||
| changes: | ||
| - description: Map threat.indicator.provider from name instead of provider. |
There was a problem hiding this comment.
Also `threat.indicator.provider` since the other fields are being rendered in <pre>.
|
/test |
|
💚 Build Succeeded
History
|
|
Package ti_threatq - 1.33.0 containing this change is available at https://epr.elastic.co/package/ti_threatq/1.33.0/ |
…der (#13137) Map threat.indicator.provider from sources.name instead of sources.provider to ensure the Total Indicators per Provider visualization is populated, as the sources.provider field is not available.
…der (#13137) Map threat.indicator.provider from sources.name instead of sources.provider to ensure the Total Indicators per Provider visualization is populated, as the sources.provider field is not available.
…der (#13137) Map threat.indicator.provider from sources.name instead of sources.provider to ensure the Total Indicators per Provider visualization is populated, as the sources.provider field is not available.
…der (#13137) Map threat.indicator.provider from sources.name instead of sources.provider to ensure the Total Indicators per Provider visualization is populated, as the sources.provider field is not available.




Type of change
Proposed commit message
threat.indicator.providerfrom sources.name instead ofsources.providerto ensure theTotal Indicators per Providervisualization is populated, as thesources.providerfield is not available.Checklist
changelog.ymlfile.How to test this PR locally