Skip to content

[m365_defender] Bugfix for when entities fields are empty - #4865

Merged
P1llus merged 2 commits into
elastic:mainfrom
P1llus:package_m365_defender_null_entities
Dec 19, 2022
Merged

[m365_defender] Bugfix for when entities fields are empty#4865
P1llus merged 2 commits into
elastic:mainfrom
P1llus:package_m365_defender_null_entities

Conversation

@P1llus

@P1llus P1llus commented Dec 19, 2022

Copy link
Copy Markdown
Member

What does this PR do?

When entities fields are empty, it will be returned as a List rather than a Map or even Null, this makes the painless conditions break, as it is expecting a Map.

This also fixed a small condition error for mapping event.category properly in certain situations.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
@P1llus
P1llus requested a review from a team as a code owner December 19, 2022 09:47
@P1llus P1llus added bug Something isn't working, use only for issues Team:Security-External Integrations Integration:m365_defender Microsoft Defender XDR labels Dec 19, 2022
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@kcreddy kcreddy left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍🏼

@ShourieG ShourieG left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@elasticmachine

elasticmachine commented Dec 19, 2022

Copy link
Copy Markdown

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2022-12-19T09:49:01.166+0000

  • Duration: 16 min 55 sec

Test stats 🧪

Test Results
Failed 0
Passed 15
Skipped 0
Total 15

🤖 GitHub comments

Expand to view the GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@elasticmachine

Copy link
Copy Markdown

🌐 Coverage report

Name Metrics % (covered/total) Diff
Packages 100.0% (2/2) 💚
Files 100.0% (2/2) 💚
Classes 100.0% (2/2) 💚
Methods 96.667% (29/30) 👎 -3.333
Lines 94.447% (2296/2431) 👎 -1.958
Conditionals 100.0% (0/0) 💚
@P1llus
P1llus merged commit b8e8203 into elastic:main Dec 19, 2022
@elasticmachine

Copy link
Copy Markdown

Package m365_defender - 1.4.2 containing this change is available at https://epr.elastic.co/search?package=m365_defender

orestisfl pushed a commit to orestisfl/integrations that referenced this pull request May 15, 2026
* [m365_defender] Bugfix for when entities fields are empty

* update changelog
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working, use only for issues Integration:m365_defender Microsoft Defender XDR

4 participants