Skip to content

trend_micro_vision_one: Support UNIX_MS date format in detection data stream - #14939

Merged
kcreddy merged 2 commits into
elastic:mainfrom
kcreddy:vision_one_rt_date_parsing
Aug 16, 2025
Merged

trend_micro_vision_one: Support UNIX_MS date format in detection data stream#14939
kcreddy merged 2 commits into
elastic:mainfrom
kcreddy:vision_one_rt_date_parsing

Conversation

@kcreddy

@kcreddy kcreddy commented Aug 14, 2025

Copy link
Copy Markdown
Contributor

Proposed commit message

trend_micro_vision_one: Support more date formats in detection data stream.

"detection" pipeline could receive date fields 
in UNIX_MS format, which is currently not 
supported. Add UNIX_MS date format option for
all the date fields.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

Run pipeline tests (with new sample data containing rt field as UNIX_MS):

Before:

--- Test results for package: trend_micro_vision_one - START ---
FAILURE DETAILS:
trend_micro_vision_one/detection test-pipeline-detection.log:
[0] unexpected pipeline error: [Failed to parse with all enclosed parsers]


╭────────────────────────┬─────────────┬───────────┬────────────────────────────────────────────────────────┬─────────────────────────────────────────────────────────────────────────────┬──────────────╮
│ PACKAGE                │ DATA STREAM │ TEST TYPE │ TEST NAME                                              │ RESULT                                                                      │ TIME ELAPSED │
├────────────────────────┼─────────────┼───────────┼────────────────────────────────────────────────────────┼─────────────────────────────────────────────────────────────────────────────┼──────────────┤
│ trend_micro_vision_one │ detection   │ pipeline  │ (ingest pipeline warnings test-pipeline-detection.log) │ PASS                                                                        │ 589.971875ms │
│ trend_micro_vision_one │ detection   │ pipeline  │ test-pipeline-detection.log                            │ FAIL: test case failed: one or more problems with fields found in documents │  92.081167ms │
╰────────────────────────┴─────────────┴───────────┴────────────────────────────────────────────────────────┴─────────────────────────────────────────────────────────────────────────────┴──────────────╯
--- Test results for package: trend_micro_vision_one - END   ---
Done

After:

--- Test results for package: trend_micro_vision_one - START ---
╭────────────────────────┬─────────────┬───────────┬────────────────────────────────────────────────────────┬────────┬──────────────╮
│ PACKAGE                │ DATA STREAM │ TEST TYPE │ TEST NAME                                              │ RESULT │ TIME ELAPSED │
├────────────────────────┼─────────────┼───────────┼────────────────────────────────────────────────────────┼────────┼──────────────┤
│ trend_micro_vision_one │ detection   │ pipeline  │ (ingest pipeline warnings test-pipeline-detection.log) │ PASS   │ 616.528916ms │
│ trend_micro_vision_one │ detection   │ pipeline  │ test-pipeline-detection.log                            │ PASS   │   97.34825ms │
╰────────────────────────┴─────────────┴───────────┴────────────────────────────────────────────────────────┴────────┴──────────────╯
--- Test results for package: trend_micro_vision_one - END   ---
Done
{"eventTimeDT":"2022-07-11T13:35:34+00:00","tags":null,"uuid":"1234abcd-1234abcd-1234abcd-1234abcd-1234abcd","searchDL":"DDL","eventTime":1657546534000,"productCode":"sig","eventName":"WEB_POLICY_VIOLATION","rt_utc":"2022-07-11T13:35:34Z","rt":"2022-07-11T13:35:34+0000","act":["Block"],"aggregatedCount":"1","detectionType":"Web Reputation Service","deviceGUID":"456xyz-456xyz-456xyz-456xyz-456xyz","dst":["81.2.69.142"],"endpointGUID":"789pqr-789pqr-789pqr-789pqr-789pqr","endpointHostName":"ABC01","fileSize":"0","fileType":"ASCII Text","osName":"10.15.6","pname":"Secure Web Gateway","policyName":"default","pver":"1.0","request":"http://example.com/","requestBase":"example.com","src":["81.2.69.142"],"suid":"user.name","urlCat":["Newly Observed Domain"],"userDomain":"example.com","profile":"Default threat protection profile","principalName":"user.name@example.com","policyUuid":"123123-abcd-123-abcd","sender":"Default cloud gateway","logKey":"123-123-123-abc-abc-abc","clientIp":["81.2.69.142"]}
{"eventTimeDT":"2022-07-11T13:35:34+00:00","tags":null,"uuid":"1234abcd-1234abcd-1234abcd-1234abcd-1234abcd","searchDL":"DDL","eventTime":1657546534000,"productCode":"sig","eventName":"WEB_POLICY_VIOLATION","rt_utc":"2022-07-11T13:35:34Z","rt":"2022-07-11T13:35:34+0000","act":["Block"],"aggregatedCount":"1","detectionType":"Web Reputation Service","deviceGUID":"456xyz-456xyz-456xyz-456xyz-456xyz","dst":["81.2.69.142"],"endpointGUID":"789pqr-789pqr-789pqr-789pqr-789pqr","endpointHostName":"ABC01","fileSize":"0","fileType":"ASCII Text","osName":"10.15.6","pname":"Secure Web Gateway","policyName":"default","pver":"1.0","requests":"http://example.com/","requestBase":"example.com","src":["81.2.69.142"],"suid":"user.name","urlCat":["Newly Observed Domain"],"userDomain":"example.com","profile":"Default threat protection profile","principalName":"user.name@example.com","policyUuid":"123123-abcd-123-abcd","sender":"Default cloud gateway","logKey":"123-123-123-abc-abc-abc","clientIp":["81.2.69.142"]}
{"act":["not blocked"],"aggregatedCount":"1","app":"SMB2","appGroup":"CIFS","aptRelated":"0","clientFlag":"src","cnt":"8","compressedFileSize":"0","dceHash1":"0","dceHash2":"0","detectionType":"1","deviceDirection":"outbound","deviceGUID":"73487B369ACB-4179A816-9CE9-24B1-C575","deviceMacAddress":"00:11:22:33:44:55","devicePayloadId":"99:10786306:::","deviceRiskConfidenceLevel":3,"dhost":"samplehost","dmac":"00:00:0b:06:bc:87","dpt":445,"dst":["81.2.69.142"],"dstGroup":"Default","dstZone":"1","dvc":["81.2.69.142"],"dvchost":"EUABCDATE09","eventId":"100119","eventName":"SECURITY_RISK_DETECTION","eventSourceType":3,"eventTime":1696921180000,"eventTimeDT":"2023-10-10T06:59:40+00:00","filePath":" ","filePathName":" ","fileSize":"0","hasdtasres":"No","interestedGroup":"Default","interestedHost":"xxx-docker","interestedIp":["192.168.47.102"],"isHidden":"Yes","logKey":"123-123-123-abc-abc-abc","malType":"OTHERS","malTypeGroup":"Others","overSsl":"Not over SSL/TLS","pComp":"NCIE","peerGroup":"Default","peerHost":"samplehost","peerIp":["81.2.69.144"],"pname":"Deep Discovery Inspector","potentialRisk":"1","productCode":"pdi","pver":"6.5.1129","remarks":"[IP address: 81.2.69.144]","rt":"2023-10-10T06:59:40.0000000Z","rtDate":"2023-10-10T00:00:00.0000000Z","rtHour":10,"rtWeekDay":"Tuesday","rt_utc":"2023-10-10T06:59:40.0000000Z","ruleId":3498,"ruleName":"DOWNLOAD FILE - SMB2(REQUEST) - BETA","searchDL":"DDL","senderGUID":"73598B359BBF-4189A816-9AD9-24B1-C475","senderIp":["81.2.69.144"],"severity":2,"shost":"sampleshost","smac":"00:00:0b:06:bc:87","spt":52066,"src":["81.2.69.144"],"srcGroup":"Default","srcZone":"1","threatType":"99","uuid":"f4c08e8d-715e-4ac9-9469-2644b7cdt959","vLANId":4085}
{"attachment":[{"attachmentFileHash":"5264bc98832d51837a1dd3705da7fe01d8f065e7","attachmentFileName":"image.png","attachmentFileSize":"-1","attachmentFileTlsh":""}],"attachmentFileHashes":["5124ba98812d51837a1dd3705da7fd00d8f067e6"],"attachmentFileHashs":["5124ba98812d51837a1dd3705da7fd00d8f067e6"],"attachmentFileName":["image.png"],"attachmentFileSizes":["-1"],"attachmentFileTlshes":[""],"attachmentFileTlshs":[""],"dataType":1,"description":"The subject (\"SOLICITAÇÃO DE CORTES SEMANA 33\") of this email is similar to known malicious mail subjects.","duser":["user@example.com.br","user2@example.com.br"],"eventId":"100009","eventName":"MESSAGE_SUSPICIOUS_DETECTION","eventSourceType":2,"eventTime":1754591294000,"eventTimeDT":"2025-08-07T18:28:14+00:00","fileCreation":"","filterRiskLevel":"info","groupId":"ec333310-1111-11e8-bb99-af11bd8888c7","groupIdCorrKey":"SUBJECT","groupIdCorrValues":["SOLICITAÇÃO DE CORTES SEMANA 33"],"logReceivedTime":"1754591305681","mailDeliveryTime":"","mailMsgDirection":21,"mailMsgSubject":"SOLICITAÇÃO DE CORTES SEMANA 33","mailReceivedTime":"","mailbox":"j.user3@example.com.br","msgId":"\u003cPPPPP80BB706167454555533336BEAA51AAAAA@AAAAAAA.aaaaaa.prod.outlook.com\u003e","msgUuid":"BBkAFgAAAAAABBBDEapmEc2byACqZY-FHg0A89ecNkvrvjJBwcWvipKPygABpXdddgAA","objectFileCreation":"","objectFileModified":"","orgId":"ec333310-1111-11e8-bb99-af11bd8888c7","pname":"Email Sensor","productCode":"xms","rt":"1754591294000","rt_utc":"2025-08-07T18:28:25.2070000Z","ruleName":"MA-01-030","ruleVer":"","samUser":"j.user3","scanTs":"","scanType":"realtime_mailmeta-exchange","searchDL":"DDL","subRuleName":"malicious_data_cluster","suser":["j.user3@example.com.br"],"tags":["XSJG.MA-01-030","MITRE.T1566.002"],"uuid":"d7777944-10c9-4197-9d97-0f8e66ef6666"}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Taken from user sample where rt field is in UNIX_MS format.

@kcreddy kcreddy self-assigned this Aug 14, 2025
@kcreddy kcreddy added enhancement New feature or request Integration:trend_micro_vision_one TrendAI Vision One Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Aug 14, 2025
@kcreddy
kcreddy marked this pull request as ready for review August 14, 2025 17:06
@kcreddy
kcreddy requested a review from a team as a code owner August 14, 2025 17:06
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@kcreddy kcreddy changed the title trend_micro_vision_one: Support more date formats in detection data stream Aug 14, 2025
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

cc @kcreddy

@kcreddy
kcreddy merged commit 88a3e23 into elastic:main Aug 16, 2025
8 of 9 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package trend_micro_vision_one - 2.3.0 containing this change is available at https://epr.elastic.co/package/trend_micro_vision_one/2.3.0/

tehbooom pushed a commit to tehbooom/integrations that referenced this pull request Nov 19, 2025
… stream (elastic#14939)

trend_micro_vision_one: Support more date formats in detection data stream.

"detection" pipeline could receive date fields 
in UNIX_MS format, which is currently not 
supported. Add UNIX_MS date format option for
all the date fields.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:trend_micro_vision_one TrendAI Vision One Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants