Skip to content

[sentinel_one] Populate ECS field message for threat, alert and activity datastreams - #13628

Merged
ShourieG merged 2 commits into
elastic:mainfrom
brijesh-elastic:sentinel_one-1.34.0
Apr 23, 2025
Merged

[sentinel_one] Populate ECS field message for threat, alert and activity datastreams#13628
ShourieG merged 2 commits into
elastic:mainfrom
brijesh-elastic:sentinel_one-1.34.0

Conversation

@brijesh-elastic

Copy link
Copy Markdown
Contributor

Proposed commit message

sentinel_one: populate ECS field message for threat, alert and activity datastreams

This will populate the correct alert title when 'External Alerts' rule is enabled.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

  • Clone integrations repo.
  • Install elastic package locally.
  • Start elastic stack using elastic-package.
  • Move to integrations/packages/sentinel_one directory.
  • Run the following command to run tests.

elastic-package test

Related issues

@brijesh-elastic brijesh-elastic added enhancement New feature or request Integration:sentinel_one SentinelOne Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] labels Apr 21, 2025
@brijesh-elastic brijesh-elastic self-assigned this Apr 21, 2025
@brijesh-elastic
brijesh-elastic requested a review from a team as a code owner April 21, 2025 14:37
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

cc @brijesh-elastic

@ShourieG ShourieG left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ShourieG
ShourieG merged commit bc19f73 into elastic:main Apr 23, 2025
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package sentinel_one - 1.34.0 containing this change is available at https://epr.elastic.co/package/sentinel_one/1.34.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:sentinel_one SentinelOne Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants