-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Make network_direction, registered_domain and convert processors compatible with ES older than 7.13.0 #26676
Make network_direction, registered_domain and convert processors compatible with ES older than 7.13.0 #26676
Conversation
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Would you mind adding a dropProcessor case for |
💚 Build Succeeded
Expand to view the summary
Build stats
Test stats 🧪
Trends 🧪💚 Flaky test reportTests succeeded. Expand to view the summary
Test stats 🧪
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. Thank you!
…atible with ES older than 7.13.0 (#26676) Adds three new Filebeat fileset compatibility tweaks to support Elasticsearch versions before 7.13.0: - Replaces usages of convert processor using type: ip with an equivalent grok expression. Convert to ip type is used to make a conditional field copy if the source field is a valid IP address. - Removes the network_direction processor. - Removes the registered_domain processor. (cherry picked from commit 65d2193)
…atible with ES older than 7.13.0 (#26676) Adds three new Filebeat fileset compatibility tweaks to support Elasticsearch versions before 7.13.0: - Replaces usages of convert processor using type: ip with an equivalent grok expression. Convert to ip type is used to make a conditional field copy if the source field is a valid IP address. - Removes the network_direction processor. - Removes the registered_domain processor. (cherry picked from commit 65d2193)
…atible with ES older than 7.13.0 (#26676) Adds three new Filebeat fileset compatibility tweaks to support Elasticsearch versions before 7.13.0: - Replaces usages of convert processor using type: ip with an equivalent grok expression. Convert to ip type is used to make a conditional field copy if the source field is a valid IP address. - Removes the network_direction processor. - Removes the registered_domain processor. (cherry picked from commit 65d2193)
…atible with ES older than 7.13.0 (#26676) (#26693) Adds three new Filebeat fileset compatibility tweaks to support Elasticsearch versions before 7.13.0: - Replaces usages of convert processor using type: ip with an equivalent grok expression. Convert to ip type is used to make a conditional field copy if the source field is a valid IP address. - Removes the network_direction processor. - Removes the registered_domain processor. (cherry picked from commit 65d2193) Co-authored-by: Adrian Serrano <adrisr83@gmail.com>
…atible with ES older than 7.13.0 (#26676) (#26691) Adds three new Filebeat fileset compatibility tweaks to support Elasticsearch versions before 7.13.0: - Replaces usages of convert processor using type: ip with an equivalent grok expression. Convert to ip type is used to make a conditional field copy if the source field is a valid IP address. - Removes the network_direction processor. - Removes the registered_domain processor. (cherry picked from commit 65d2193) Co-authored-by: Adrian Serrano <adrisr83@gmail.com>
… convert processors compatible with ES older than 7.13.0 (#26692) Adds three new Filebeat fileset compatibility tweaks to support Elasticsearch versions before 7.13.0: - Replaces usages of convert processor using type: ip with an equivalent grok expression. Convert to ip type is used to make a conditional field copy if the source field is a valid IP address. - Removes the network_direction processor. - Removes the registered_domain processor. (cherry picked from commit 65d2193) * Fix changelog Co-authored-by: Adrian Serrano <adrisr83@gmail.com>
…stage-failed-within-same-build * upstream/master: (36 commits) Revert "[CI] fight the flakiness with some retry option in the CI only for the Pull Requests (elastic#26617)" (elastic#26704) Packaging: linux/armv7 is not supported (elastic#26706) Cyberarkpas: Link to official docs on how to setup TLS (elastic#26614) Make network_direction, registered_domain and convert processors compatible with ES older than 7.13.0 (elastic#26676) Disable armv7 packaging (elastic#26679) [Heartbeat] use --params flag for synthetics (elastic#26674) Update dependent package to avoid downloading a suspicious file (elastic#26406) [mergify] set title and allow bp in any direction (elastic#26648) Fix memory leak in SQL helper when database is not available (elastic#26607) [CI] fight the flakiness with some retry option in the CI only for the Pull Requests (elastic#26617) [mergify] automate PRs that change the backport rules (elastic#26641) [Metricbeat] Add Airflow module in xpack (elastic#26220) chore: add-backport-next (elastic#26620) [metricbeat] Add state_job metricset (elastic#26479) CI: jenkins labels are less time consuming now (elastic#26613) [MetricBeat] [AWS] Fix aws metric tags with resourcegroupstaggingapi paginator (elastic#26385) (elastic#26443) Move openmetrics module to oss (elastic#26561) Skip flaky test TestFilestreamMetadataUpdatedOnRename (elastic#26609) [filebeat][fortinet] Use default add_locale for fortinet.firewall (elastic#26524) Enroll proxy settings (elastic#26514) ...
What does this PR do?
Adds three new Filebeat fileset compatibility tweaks to support Elasticsearch versions before 7.13.0:
convert
processor usingtype: ip
with an equivalentgrok
expression. Convert to ip type is used to make a conditional field copy if the source field is a valid IP address.network_direction
processor.registered_domain
processor.Why is it important?
To ensure modules work with versions older than 7.13.0.
Checklist
My code follows the style guidelines of this project
I have commented my code, particularly in hard-to-understand areas
[ ] I have made corresponding changes to the documentation[ ] I have made corresponding change to the default configuration filesI have added tests that prove my fix is effective or that my feature works
I have added an entry in
CHANGELOG.next.asciidoc
orCHANGELOG-developer.next.asciidoc
.Relates [Filebeat] Module incompatibility with older ES/Kibana versions #26629
Relates [Filebeat] Replace copy_from with templated value #26631