Skip to content

[AbuseCH] Adds new ECS fields - #2293

Merged
P1llus merged 3 commits into
elastic:masterfrom
P1llus:abusech_threatname
Dec 8, 2021
Merged

[AbuseCH] Adds new ECS fields#2293
P1llus merged 3 commits into
elastic:masterfrom
P1llus:abusech_threatname

Conversation

@P1llus

@P1llus P1llus commented Dec 1, 2021

Copy link
Copy Markdown
Member

What does this PR do?

Adds threat.feed.name and threat.feed.dashboard_id ECS fields.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@elasticmachine

elasticmachine commented Dec 1, 2021

Copy link
Copy Markdown

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2021-12-07T09:07:30.880+0000

  • Duration: 18 min 56 sec

  • Commit: b7365b3

Test stats 🧪

Test Results
Failed 0
Passed 18
Skipped 0
Total 18

🤖 GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.
@efd6

efd6 commented Dec 3, 2021

Copy link
Copy Markdown
Contributor

Are these fields in ECS? I couldn't find them.

@P1llus

P1llus commented Dec 6, 2021

Copy link
Copy Markdown
Member Author

Are these fields in ECS? I couldn't find them.

They are not in ECS yet, but are coming. We will need to add them for 8.0 either way currently.

Comment thread packages/ti_abusech/data_stream/malware/elasticsearch/ingest_pipeline/default.yml Outdated
@P1llus
P1llus merged commit b420864 into elastic:master Dec 8, 2021
orestisfl pushed a commit to orestisfl/integrations that referenced this pull request May 15, 2026
* add threat feed name and dashboard_id

* update changelog

* update fields to constant keywords
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

4 participants