Skip to content

microsoft_sentinel, google_secops: Make packages GA - #13534

Merged
kcreddy merged 2 commits into
elastic:mainfrom
kcreddy:microsoft_sent-google_scc-ga
Apr 15, 2025
Merged

microsoft_sentinel, google_secops: Make packages GA#13534
kcreddy merged 2 commits into
elastic:mainfrom
kcreddy:microsoft_sent-google_scc-ga

Conversation

@kcreddy

@kcreddy kcreddy commented Apr 14, 2025

Copy link
Copy Markdown
Contributor

Proposed commit message

Release microsoft_sentinel and google_secops packages as GA.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

@kcreddy
kcreddy marked this pull request as ready for review April 14, 2025 13:58
@kcreddy
kcreddy requested a review from a team as a code owner April 14, 2025 13:58
@kcreddy kcreddy self-assigned this Apr 14, 2025
@kcreddy kcreddy added Integration:microsoft_sentinel Microsoft Sentinel Integration:google_secops Google SecOps Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Apr 14, 2025
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@kcreddy kcreddy added the enhancement New feature or request label Apr 14, 2025
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

cc @kcreddy

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggest addressing #12083 in this for microsoft_sentinel?

@kcreddy

kcreddy commented Apr 15, 2025

Copy link
Copy Markdown
Contributor Author

Suggest addressing #12083 in this for microsoft_sentinel?

@efd6, does updating fail to a terminate processor make this second error from error.message: #12731 (comment) disappear?

The fail processor in Microsoft Sentinel is similar here. Its to stop the pipeline because of an error from CEL.

@efd6

efd6 commented Apr 15, 2025

Copy link
Copy Markdown
Contributor

@kcreddy If that's the only fail that's used (it is), I'm fine with leaving it as is for this PR; it is a little bit of noise in the index, but it's not terrible. If we want to change all the CEL failure fails to terminates, then I think they probably should all happen at once.

@kcreddy
kcreddy merged commit 6ec77fe into elastic:main Apr 15, 2025
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package google_secops - 1.0.0 containing this change is available at https://epr.elastic.co/package/google_secops/1.0.0/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package microsoft_sentinel - 1.0.0 containing this change is available at https://epr.elastic.co/package/microsoft_sentinel/1.0.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:google_secops Google SecOps Integration:microsoft_sentinel Microsoft Sentinel Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants