Update SentinelOne Threat Pipline to Set event.id for ECS [Enhancement] - #4840
Conversation
Adding ECS event.id Field from SentinelOne Threat ID
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
|
Hi together, any updates when this is going to be fixed? |
kcreddy
left a comment
There was a problem hiding this comment.
Please add changelog.yml and manifest.yml entries to the PR
|
Hi @kcreddy All Required Files should be edited now! Regards Christoph |
@ChriZzn please also update This is the place you need to change it to |
|
Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as |
|
Not stale - waiting on manifest to be updated. |
|
Hi, should be done now! Regards Christoph |
|
@ChriZzn you will need to bump up the version to A version upgrade already happened on the package as you can see earlier it was Also, could you answer this as well? #4840 (comment) |
|
Hi @kcreddy should be done now. Regards Christoph |
|
/test |
🌐 Coverage report
|
|
/test |
|
@ChriZzn are you able to run |
|
Hi, now we have no ability to run this |
|
OK. I'll add this. |
|
/test |
Hey @efd6 I have taken care of it. |
|
Package sentinel_one - 1.5.1 containing this change is available at https://epr.elastic.co/search?package=sentinel_one |
…t] (elastic#4840) * Update default.yml Adding ECS event.id Field from SentinelOne Threat ID * Update changelog.yml * Update manifest.yml * Update manifest.yml * Update changelog.yml * Update changelog.yml * Add tests; Update readme --------- Co-authored-by: kcreddy <krish.reddy91@gmail.com>
Adding ECS event.id Field from SentinelOne Threat ID
What does this PR do?
Addint the event.id Field this discribes the Unique Threat ID in SentinelOne
Checklist
changelog.ymlfile.