feat: Preserve event.original when pipeline errors in integration-experience integrations (part 4) - #15806
Conversation
- Added append processor to global on_failure to preserve event original - Added append processor to default pipelines to preserve event original if error.message is set Affects the following integrations: - sophos - squid - stormshield - suricata - syslog_router - tetragon - watchguard_firebox - zeek
e65a9c2 to
fe91965
Compare
💚 Build Succeeded
|
|
Pinging @elastic/integration-experience (Team:Integration-Experience) |
|
Package cilium_tetragon - 0.3.0 containing this change is available at https://epr.elastic.co/package/cilium_tetragon/0.3.0/ |
|
Package sophos - 3.16.0 containing this change is available at https://epr.elastic.co/package/sophos/3.16.0/ |
|
Package squid - 1.4.0 containing this change is available at https://epr.elastic.co/package/squid/1.4.0/ |
|
Package stormshield - 1.4.0 containing this change is available at https://epr.elastic.co/package/stormshield/1.4.0/ |
|
Package suricata - 2.26.0 containing this change is available at https://epr.elastic.co/package/suricata/2.26.0/ |
|
Package syslog_router - 0.4.0 containing this change is available at https://epr.elastic.co/package/syslog_router/0.4.0/ |
|
Package watchguard_firebox - 1.5.0 containing this change is available at https://epr.elastic.co/package/watchguard_firebox/1.5.0/ |
|
Package zeek - 3.1.0 containing this change is available at https://epr.elastic.co/package/zeek/3.1.0/ |
…#15806) - Added append processor to global on_failure to preserve event original - Added append processor to default pipelines to preserve event original if error.message is set Affects the following integrations: - sophos - squid - stormshield - suricata - syslog_router - tetragon - watchguard_firebox - zeek
Proposed commit message
event.original.error.messageis set.Integrations
Checklist
changelog.ymlfile.- [ ] I have verified that any added dashboard complies with Kibana's Dashboard good practicesRelated issues