Fix durationMs parsing in auditlogs data stream - #16674
Merged
Merged
Conversation
|
💚 CLA has been signed |
Contributor
|
Hey @gregorywychowaniec-zt, thanks for raising this PR! 🙇 I'll open an issue/PR to fix this field across all Azure integrations. |
zmoog
approved these changes
Dec 23, 2025
zmoog
left a comment
Contributor
There was a problem hiding this comment.
LGTM, thanks for fixing this @gregorywychowaniec-zt.
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
kcreddy
approved these changes
Dec 23, 2025
ShourieG
reviewed
Dec 23, 2025
Contributor
|
I created the issue #16677 to normalize |
ShourieG
approved these changes
Dec 23, 2025
Kavindu-Dodan
approved these changes
Dec 23, 2025
Contributor
|
@gregorywychowaniec-zt I have resolved the merge conflict and with current approvals, this should be good to go |
devamanv
approved these changes
Dec 24, 2025
Signed-off-by: Kavindu Dodanduwa <kavindu.dodanduwa@elastic.co>
Kavindu-Dodan
enabled auto-merge (squash)
December 29, 2025 18:27
Signed-off-by: Kavindu Dodanduwa <kavindu.dodanduwa@elastic.co>
Contributor
|
/test |
Contributor
🚀 Benchmarks reportTo see the full report comment with |
💚 Build Succeeded
History
cc @zmoog |
Contributor
|
Package azure - 1.34.1 containing this change is available at https://epr.elastic.co/package/azure/1.34.1/ |
smnschndr
added a commit
to smnschndr/integrations
that referenced
this pull request
Jul 28, 2026
…ity_protection, provisioning, springcloudlogs Some Azure services emit durationMs as a string instead of a number. The auditlogs data stream already guards against this (fixed in elastic#16674); platformlogs was unaffected from the start. The other five data streams still did a plain rename of durationMs into event.duration, so a string value passed through unconverted: the nanosecond-multiplication script right after it fails silently (ignore_failure: true) for a String operand, leaving event.duration as a raw millisecond string instead of a long-typed nanosecond value. This causes ES mapping conflicts on event.duration. Applied the same convert-if-string / rename-if-not-string / remove pattern already used in auditlogs to all five remaining data streams. Added a pipeline test per data stream reproducing durationMs as a string, verified end-to-end against a live Elasticsearch instance via `elastic-package test pipeline --generate`: - activitylogs: "0" -> event.duration = 0 - eventhub: "0" -> event.duration = 0 - identity_protection: "0" -> event.duration = 0 - provisioning: "828" -> event.duration = 828000000 - springcloudlogs: "12" -> event.duration = 12000000 All 40 existing and new pipeline tests pass (elastic-package test pipeline). Fixes elastic#16677 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01STTaWPq6nDxykUYmFe73D3
smnschndr
added a commit
to smnschndr/integrations
that referenced
this pull request
Jul 28, 2026
…ity_protection, provisioning, springcloudlogs Some Azure services emit durationMs as a string instead of a number. The auditlogs data stream already guards against this (fixed in elastic#16674); platformlogs was unaffected from the start. The other five data streams still did a plain rename of durationMs into event.duration, so a string value passed through unconverted: the nanosecond-multiplication script right after it fails silently (ignore_failure: true) for a String operand, leaving event.duration as a raw millisecond string instead of a long-typed nanosecond value. This causes ES mapping conflicts on event.duration. Applied the same convert-if-string / rename-if-not-string / remove pattern already used in auditlogs to all five remaining data streams. Added a pipeline test per data stream reproducing durationMs as a string, verified end-to-end against a live Elasticsearch instance via `elastic-package test pipeline --generate`: - activitylogs: "0" -> event.duration = 0 - eventhub: "0" -> event.duration = 0 - identity_protection: "0" -> event.duration = 0 - provisioning: "828" -> event.duration = 828000000 - springcloudlogs: "12" -> event.duration = 12000000 All 40 existing and new pipeline tests pass (elastic-package test pipeline). Fixes elastic#16677 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01STTaWPq6nDxykUYmFe73D3
smnschndr
added a commit
to smnschndr/integrations
that referenced
this pull request
Jul 28, 2026
…ity_protection, provisioning, springcloudlogs Some Azure services emit durationMs as a string instead of a number. The auditlogs data stream already guards against this (fixed in elastic#16674); platformlogs was unaffected from the start. The other five data streams still did a plain rename of durationMs into event.duration, so a string value passed through unconverted: the nanosecond-multiplication script right after it fails silently (ignore_failure: true) for a String operand, leaving event.duration as a raw millisecond string instead of a long-typed nanosecond value. This causes ES mapping conflicts on event.duration. Applied the same convert-if-string / rename-if-not-string / remove pattern already used in auditlogs to all five remaining data streams, including matching processor tags (missing on the original auditlogs processors, added here per current pipeline conventions). Added a pipeline test per data stream reproducing durationMs as a string, verified end-to-end against a live Elasticsearch instance via `elastic-package test pipeline --generate`: - activitylogs: "0" -> event.duration = 0 - eventhub: "50" -> event.duration = 50000000 - identity_protection: "0" -> event.duration = 0 - provisioning: "828" -> event.duration = 828000000 - springcloudlogs: "12" -> event.duration = 12000000 The eventhub fixture required an explicit `tags: [parse_message]` config, since default.yml only routes into parsed-message.yml (the file this fix touches) when that tag is set -- without it, the test would have silently passed without exercising the fix at all. Fixture filenames follow the `test-<package>-<datastream>-<type>-sample.log` convention; the identity_protection fixture omits the underscore (`identityprotection`) since package-spec rejects underscores in this file name segment. Verified with a full `elastic-package check` (lint + build) and the complete pipeline test suite for the whole azure package (not just the 5 touched data streams) in a clean, non-worktree clone -- all green, no regressions. Fixes elastic#16677 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01STTaWPq6nDxykUYmFe73D3
smnschndr
added a commit
to smnschndr/integrations
that referenced
this pull request
Jul 30, 2026
…ity_protection, provisioning, springcloudlogs Some Azure services emit durationMs as a string instead of a number. The auditlogs data stream already guards against this (fixed in elastic#16674); platformlogs was unaffected from the start. The other five data streams still did a plain rename of durationMs into event.duration, so a string value passed through unconverted: the nanosecond-multiplication script right after it fails silently (ignore_failure: true) for a String operand, leaving event.duration as a raw millisecond string instead of a long-typed nanosecond value. This causes ES mapping conflicts on event.duration. Applied the same convert-if-string / rename-if-not-string / remove pattern already used in auditlogs to all five remaining data streams, including matching processor tags (missing on the original auditlogs processors, added here per current pipeline conventions). Added a pipeline test per data stream reproducing durationMs as a string, verified end-to-end against a live Elasticsearch instance via `elastic-package test pipeline --generate`: - activitylogs: "0" -> event.duration = 0 - eventhub: "50" -> event.duration = 50000000 - identity_protection: "0" -> event.duration = 0 - provisioning: "828" -> event.duration = 828000000 - springcloudlogs: "12" -> event.duration = 12000000 The eventhub fixture required an explicit `tags: [parse_message]` config, since default.yml only routes into parsed-message.yml (the file this fix touches) when that tag is set -- without it, the test would have silently passed without exercising the fix at all. Fixture filenames follow the `test-<package>-<datastream>-<type>-sample.log` convention; the identity_protection fixture omits the underscore (`identityprotection`) since package-spec rejects underscores in this file name segment. Verified with a full `elastic-package check` (lint + build) and the complete pipeline test suite for the whole azure package (not just the 5 touched data streams) in a clean, non-worktree clone -- all green, no regressions. Fixes elastic#16677 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01STTaWPq6nDxykUYmFe73D3
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed commit message
Same as encoutered in #15976, we got some auditlogs with durationMs as a string that break the pipeline. So same fix for auditlogs here :
azure.auditlogs.durationMsaslongtype if the value comes as stringChecklist
changelog.ymlfile.How to test this PR locally