multiple: update transform mapping - #19055
Conversation
{m365_defender, aws, aws_securityhub, google_scc, microsoft_defender_cloud, microsoft_defender_endpoint, prisma_cloud, qualys_vmdr, rapid7_inishgtvm, teneable_io, wiz}
Addresses config not addressed by #14809
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
🚀 Benchmarks reportTo see the full report comment with |
efd6
left a comment
There was a problem hiding this comment.
I think this is the wrong place to fix this. If it's needed (it is), we should make it possible for a type: constant_keyword to be redefined as a type: keyword. This would be a change in github.com/elastic/elastic-package in the allow list in allowedTypeOverride.
Note that the changes here are bug-fixes (ref) and so should bump patch.
cc @jsoriano
Co-authored-by: mmahacek <mark@mahacek.net>
|
@efd6 Thanks for the feedback. It does look like the I updated this PR to bump the versions down from minor to patch, since these packages would need to be rebuilt to get the correct mapping applied after updating the elastic-package anyway. |
💚 Build Succeeded
History
cc @mmahacek |
|
@mmahacek The elastic-package issue appears to be aligned with ecosystem, so I'd suggest that you send that change. It won't be available for a while, so we should also go ahead with this as an interim fix, but I'd like to see the documentation for the fields defined in ECS be copied over to the local definitions here so that there is not a documentation regression. Then the future follow up would be to revert to the |
|
@efd6 I'm not on the dev team, and not fluent in Go, so I'm not going to submit any code changes for the elastic-package repo. I've got a issue reported there for someone on that team to pick up. It also looks like my permissions on this repo have been updated, so I no longer have push access to my branch. I either need someone to update the AWS version since there's a conflict with another patch that has been pushed, or I need to cancel this PR and re-submit from a fork. |
|
@mmahacek I've sent elastic/elastic-package#3605. |
Pull request was closed
{m365_defender, aws, aws_securityhub, google_scc, microsoft_defender_cloud, microsoft_defender_endpoint, prisma_cloud, qualys_vmdr, rapid7_inishgtvm, teneable_io, wiz} Addresses config not addressed by #14809
Proposed commit message
{m365_defender, aws, aws_securityhub, google_scc, microsoft_defender_cloud, microsoft_defender_endpoint, prisma_cloud, qualys_vmdr, rapid7_inishgtvm, teneable_io, wiz} Addresses transform mapping not addressed by #14809
Checklist
changelog.ymlfile.Author's Checklist
How to test this PR locally
Verify component template for the transforms mention in the PR have
data_stream.namespaceproperly mapped askeywordRelated issues
data_stream.namespacemapping error on transforms #19054Screenshots
n/a