Skip to content

[SOPHOS UTM] Add GeopIP conditions - #15130

Merged
qcorporation merged 4 commits into
elastic:mainfrom
SimonKoetting:sophos_utm_fix_empty_geoip
Sep 16, 2025
Merged

[SOPHOS UTM] Add GeopIP conditions#15130
qcorporation merged 4 commits into
elastic:mainfrom
SimonKoetting:sophos_utm_fix_empty_geoip

Conversation

@SimonKoetting

Copy link
Copy Markdown
Contributor

Prevent pipeline errors if source/destionation .ip is a empty string

@SimonKoetting
SimonKoetting requested a review from a team as a code owner September 2, 2025 13:39
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@andrewkroh andrewkroh added Integration:sophos Sophos Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience] labels Sep 2, 2025
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/integration-experience (Team:Integration-Experience)

@qcorporation qcorporation left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes look OK.
Question: are you not seeing these type of behaviour within any of the other geoip: process.
I see similar processing within

  • utm/../dhcp.yml
  • utm/../dns.yml
  • xg/../default.yml
Comment thread packages/sophos/changelog.yml Outdated
@SimonKoetting

Copy link
Copy Markdown
Contributor Author

I observed the issue so far just on the http & packet filter, but you're right, it's the same on the other geoip processors. I added that as well

@qcorporation
qcorporation requested a review from a team September 4, 2025 17:25

@qcorporation qcorporation left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@qcorporation
qcorporation enabled auto-merge (squash) September 16, 2025 12:55
@qcorporation
qcorporation merged commit 5068ae8 into elastic:main Sep 16, 2025
7 checks passed
@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package sophos - 3.15.2 containing this change is available at https://epr.elastic.co/package/sophos/3.15.2/

tehbooom pushed a commit to tehbooom/integrations that referenced this pull request Nov 19, 2025
* [SOPHOS UTM] Add GeopIP conditions
Prevent pipeline errors if source/destionation .ip is a empty string
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Integration:sophos Sophos Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience]

4 participants