Skip to content

[ti_threatq] fix template evaluation to prevent updating fleet health status to degraded - #16686

Merged
brijesh-elastic merged 2 commits into
elastic:mainfrom
brijesh-elastic:ti_threatq-1.37.0
Dec 24, 2025
Merged

[ti_threatq] fix template evaluation to prevent updating fleet health status to degraded#16686
brijesh-elastic merged 2 commits into
elastic:mainfrom
brijesh-elastic:ti_threatq-1.37.0

Conversation

@brijesh-elastic

Copy link
Copy Markdown
Contributor

Proposed commit message

ti_threatq: don't update fleet health status to degraded pagination completes

It also corrects the output response JSON in the system test config rules. I've verified the
response structure against the live API.

This change bumps minimum Kibana version to ^8.19.4 || ~9.0.7 || ^9.1.4 and adds
`do_not_log_failure: true` in set transforms to avoid updating
fleet health status to degraded.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

  • Clone integrations repo.
  • Install elastic package locally.
  • Start elastic stack using elastic-package.
  • Move to integrations/packages/ti_threatq directory.
  • Run the following command to run tests.

elastic-package test

Related issues

@brijesh-elastic brijesh-elastic self-assigned this Dec 24, 2025
@brijesh-elastic
brijesh-elastic requested a review from a team as a code owner December 24, 2025 07:02
@brijesh-elastic brijesh-elastic added documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:ti_threatq ThreatQuotient (Partner supported) Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] labels Dec 24, 2025
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

cc @brijesh-elastic

@brijesh-elastic
brijesh-elastic merged commit b832d2c into elastic:main Dec 24, 2025
8 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package ti_threatq - 1.37.0 containing this change is available at https://epr.elastic.co/package/ti_threatq/1.37.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:ti_threatq ThreatQuotient (Partner supported) Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants