Skip to content

[KeyClock] Set the ECS field event.outcome based on the value of keycloak.login.type - #14027

Merged
efd6 merged 3 commits into
elastic:mainfrom
moxarth-rathod:keyclock-enhancement
May 28, 2025
Merged

[KeyClock] Set the ECS field event.outcome based on the value of keycloak.login.type#14027
efd6 merged 3 commits into
elastic:mainfrom
moxarth-rathod:keyclock-enhancement

Conversation

@moxarth-rathod

Copy link
Copy Markdown
Contributor

Proposed commit message

keycloak: parse event.outcome field

This PR sets the ecs field `event.outcome` based on the value of `keycloak.login.type`.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

  • Clone integrations repo.
  • Install elastic package locally.
  • Start elastic stack using elastic-package.
  • Move to integrations/packages/keyclock directory.
  • Run the following command to run tests.

elastic-package test

@moxarth-rathod moxarth-rathod self-assigned this May 28, 2025
@moxarth-rathod
moxarth-rathod requested a review from a team as a code owner May 28, 2025 09:19
@moxarth-rathod moxarth-rathod added enhancement New feature or request Integration:keycloak Keycloak Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] labels May 28, 2025
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @moxarth-rathod

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@efd6
efd6 merged commit e84deaf into elastic:main May 28, 2025
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package keycloak - 1.28.0 containing this change is available at https://epr.elastic.co/package/keycloak/1.28.0/

anupratharamachandran pushed a commit to anupratharamachandran/integrations that referenced this pull request Jun 2, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:keycloak Keycloak Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants