Skip to content

[8.14] API event field updates #479

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 14 commits into from
Apr 3, 2024
Merged

[8.14] API event field updates #479

merged 14 commits into from
Apr 3, 2024

Conversation

jdu2600
Copy link
Contributor

@jdu2600 jdu2600 commented Mar 21, 2024

Change Summary

  • Add Target.process.Ext.protection field to API events - added in 8.13.0 (and 8.12.3)
  • Add [Target.]process.Ext.created_suspended field to process and API events - new for 8.14.0
  • Add connect() parameter fields to API events - new in 8.14.0
  • Add TCP/IP metadata source fields - new in 8.14.0

For mapping changes:

  • I ran make after making the schema changes, and committed all changes
  • If these field(s) are "exception"-able, I made a companion PR to Kibana adding it (see Readme)
  • If this is a metadata change, I also updated both transform destination schemas to match

@jdu2600 jdu2600 requested a review from a team as a code owner March 21, 2024 05:26
@jdu2600 jdu2600 requested review from tomsonpl and parkiino March 21, 2024 05:26
@jdu2600 jdu2600 requested a review from a team as a code owner March 21, 2024 06:06
@jdu2600 jdu2600 requested a review from gabriellandau March 22, 2024 00:51
* add connect parameters

* add generated files
@jdu2600 jdu2600 changed the title [8.14] process.Ext.created_suspended [8.14] API event field updates Mar 22, 2024
@jdu2600 jdu2600 marked this pull request as draft March 26, 2024 03:43
@jdu2600 jdu2600 marked this pull request as ready for review March 28, 2024 05:23
@jdu2600 jdu2600 requested a review from gabriellandau March 28, 2024 05:23
Copy link
Contributor

@gabriellandau gabriellandau left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚀

@jdu2600
Copy link
Contributor Author

jdu2600 commented Apr 2, 2024

@elastic/security-defend-workflows - any further feedback on this PR?

Copy link
Member

@pzl pzl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

good to merge

@jdu2600
Copy link
Contributor Author

jdu2600 commented Apr 3, 2024

Thanks @gabriellandau @pzl

@jdu2600 jdu2600 merged commit 2e0fb6e into main Apr 3, 2024
@jdu2600 jdu2600 deleted the 8.14_process_create_suspended branch April 3, 2024 00:02
@elasticmachine
Copy link
Contributor

Package endpoint - 8.14.0 containing this change is available at https://epr.elastic.co/search?package=endpoint

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants