[Carbon Black Cloud] - Added alerts v7 data stream and CEL input type - #9467
Conversation
…tation for making integration GA
…ferent types of alerts
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
This reverts commit 7debf07.
|
@efd6 addressed all the PR suggestions |
There was a problem hiding this comment.
Sorry for the late review. I saw it late that my name was tagged 😄 .
For the ones moving from httpjson to CEL, how does the upgrade process looks like in the UI, say from 1.21.3 to 2.0.0? Do they end up still using httpjson or migrate to CEL seamlessly or prompted to configure CEL input?
@kcreddy So atm after upgrading to 2.0, httpjson is still there and if they have httpjson configured it will still stay active, CEL will be an additional input that can they will see and choose to migrate over if they wish to. |
…d relative fields to ecs process & process.parent objects
kcreddy
left a comment
There was a problem hiding this comment.
LGTM 👍🏼 for my comments.
💚 Build Succeeded
History
cc @ShourieG |
|
|
Package carbon_black_cloud - 2.0.0 containing this change is available at https://epr.elastic.co/search?package=carbon_black_cloud |

92.3% Coverage on New Code
0.0% Duplication on New Code
Type of change
Proposed commit message
Added a new alerts_v7 data stream to mirror the v7 api and schema changes from carbon black cloud.
The old data stream has not been removed in order to allow smooth transition to the new v7 data stream once the old api stops working. This avoids a breaking change. In addition to this a new CEL input option has been introduced to bring more flexibility for the future. This new input has been tagged as [Beta] while the existing HTTPJSON input has been tagged as [Legacy]. This was done in order to smoothen the transition overtime and avoid breaking changes.
Checklist
changelog.ymlfile.Author's Checklist
Note
How to test this PR locally
Clone integrations repo.
Install the elastic package locally.
Start the elastic stack using the elastic package stack up command.
Move to integrations/packages/carbon_black_cloud directory.
Run the following command to run tests.
Related issues
Test Results
Screenshots
Add here screenshots presenting:
Dashboards with collected metrics or logs:
Alerts V7 (Samples):
Asset Vulnerability:
Audit Logs: