Skip to content

[amazon_security_lake] Parse JSON in ocsf.resources.data, ocsf.unmapped - #15167

Merged
chrisberkhout merged 4 commits into
elastic:mainfrom
chrisberkhout:amazon_security_lake-parse-json-for-flattened
Sep 5, 2025
Merged

[amazon_security_lake] Parse JSON in ocsf.resources.data, ocsf.unmapped#15167
chrisberkhout merged 4 commits into
elastic:mainfrom
chrisberkhout:amazon_security_lake-parse-json-for-flattened

Conversation

@chrisberkhout

@chrisberkhout chrisberkhout commented Sep 4, 2025

Copy link
Copy Markdown
Contributor

Proposed commit message

[amazon_security_lake] Parse JSON in `ocsf.resources.data`, `ocsf.unmapped`

In case these fields are JSON strings rather than objects, parse them so
that they can be indexed as flattened.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

@chrisberkhout chrisberkhout self-assigned this Sep 4, 2025
@chrisberkhout
chrisberkhout requested a review from a team as a code owner September 4, 2025 21:02
@chrisberkhout chrisberkhout added bugfix Pull request that fixes a bug issue Integration:amazon_security_lake Amazon Security Lake Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Sep 4, 2025
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@chrisberkhout
chrisberkhout force-pushed the amazon_security_lake-parse-json-for-flattened branch from fb068b2 to dab24b6 Compare September 5, 2025 07:28
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @chrisberkhout

@chrisberkhout
chrisberkhout merged commit 29b7642 into elastic:main Sep 5, 2025
9 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package amazon_security_lake - 2.7.1 containing this change is available at https://epr.elastic.co/package/amazon_security_lake/2.7.1/

tehbooom pushed a commit to tehbooom/integrations that referenced this pull request Nov 19, 2025
…apped` (elastic#15167)

In case these fields are JSON strings rather than objects, parse them so
that they can be indexed as flattened.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue Integration:amazon_security_lake Amazon Security Lake Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants