Skip to content

Support stack 9.0 in deployment and devices integrations #13042

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Mar 10, 2025

Conversation

taylor-swanson
Copy link
Contributor

@taylor-swanson taylor-swanson commented Mar 10, 2025

Proposed commit message

  • Support stack 9.0 in integrations owned by deployment and devices

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
    - [ ] I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

- Support stack 9.0 in integrations owned by deployment and devices
@taylor-swanson taylor-swanson added enhancement New feature or request Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices] labels Mar 10, 2025
@taylor-swanson taylor-swanson self-assigned this Mar 10, 2025
@elastic-vault-github-plugin-prod
Copy link

elastic-vault-github-plugin-prod bot commented Mar 10, 2025

🚀 Benchmarks report

Package checkpoint 👍(0) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
firewall 1490.31 1204.82 -285.49 (-19.16%) 💔

Package cisco_aironet 👍(0) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
log 3412.97 2739.73 -673.24 (-19.73%) 💔

Package fortinet_fortiproxy 👍(0) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
log 1190.48 890.47 -300.01 (-25.2%) 💔

Package goflow2 👍(0) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
sflow 3676.47 2352.94 -1323.53 (-36%) 💔

Package modsecurity 👍(0) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
auditlog 528.82 417.71 -111.11 (-21.01%) 💔

Package snort 👍(0) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
log 22222.22 15384.62 -6837.6 (-30.77%) 💔

Package squid 👍(0) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
log 5681.82 3891.05 -1790.77 (-31.52%) 💔

Package syslog_router 👍(0) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
log 125000 62500 -62500 (-50%) 💔

Package zeek 👍(19) 💚(14) 💔(10)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
irc 37037.04 22727.27 -14309.77 (-38.64%) 💔
notice 38461.54 30303.03 -8158.51 (-21.21%) 💔
capture_loss 18867.92 12987.01 -5880.91 (-31.17%) 💔
ntlm 26315.79 21276.6 -5039.19 (-19.15%) 💔
ntp 43478.26 17857.14 -25621.12 (-58.93%) 💔
radius 17241.38 10204.08 -7037.3 (-40.82%) 💔
ssl 37037.04 31250 -5787.04 (-15.63%) 💔
weird 37037.04 29411.76 -7625.28 (-20.59%) 💔
dnp3 22727.27 15384.62 -7342.65 (-32.31%) 💔
ftp 33333.33 27777.78 -5555.55 (-16.67%) 💔

To see the full report comment with /test benchmark fullreport

@taylor-swanson taylor-swanson marked this pull request as ready for review March 10, 2025 16:42
@taylor-swanson taylor-swanson requested a review from a team as a code owner March 10, 2025 16:42
@elasticmachine
Copy link

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)

@taylor-swanson taylor-swanson enabled auto-merge (squash) March 10, 2025 18:24
@taylor-swanson taylor-swanson merged commit 3dfbf05 into elastic:main Mar 10, 2025
5 checks passed
Copy link

@elasticmachine
Copy link

💚 Build Succeeded

History

cc @taylor-swanson

@taylor-swanson taylor-swanson deleted the enhance/dnd-stack-9 branch March 10, 2025 19:24
@elastic-vault-github-plugin-prod

Package arista_ngfw - 1.4.0 containing this change is available at https://epr.elastic.co/package/arista_ngfw/1.4.0/

@elastic-vault-github-plugin-prod

Package cef - 2.21.0 containing this change is available at https://epr.elastic.co/package/cef/2.21.0/

@elastic-vault-github-plugin-prod

Package checkpoint - 1.39.0 containing this change is available at https://epr.elastic.co/package/checkpoint/1.39.0/

@elastic-vault-github-plugin-prod

Package cilium_tetragon - 0.2.0 containing this change is available at https://epr.elastic.co/package/cilium_tetragon/0.2.0/

@elastic-vault-github-plugin-prod

Package cisco_aironet - 1.16.0 containing this change is available at https://epr.elastic.co/package/cisco_aironet/1.16.0/

@elastic-vault-github-plugin-prod

Package cisco_asa - 2.43.0 containing this change is available at https://epr.elastic.co/package/cisco_asa/2.43.0/

@elastic-vault-github-plugin-prod

Package cisco_ftd - 3.8.0 containing this change is available at https://epr.elastic.co/package/cisco_ftd/3.8.0/

@elastic-vault-github-plugin-prod

Package cisco_ios - 1.30.0 containing this change is available at https://epr.elastic.co/package/cisco_ios/1.30.0/

@elastic-vault-github-plugin-prod

Package cisco_ise - 1.26.0 containing this change is available at https://epr.elastic.co/package/cisco_ise/1.26.0/

@elastic-vault-github-plugin-prod

Package cisco_nexus - 1.4.0 containing this change is available at https://epr.elastic.co/package/cisco_nexus/1.4.0/

@elastic-vault-github-plugin-prod

Package cisco_secure_email_gateway - 1.26.0 containing this change is available at https://epr.elastic.co/package/cisco_secure_email_gateway/1.26.0/

@elastic-vault-github-plugin-prod

Package citrix_waf - 1.18.0 containing this change is available at https://epr.elastic.co/package/citrix_waf/1.18.0/

@elastic-vault-github-plugin-prod

Package fortinet_fortiedr - 1.18.0 containing this change is available at https://epr.elastic.co/package/fortinet_fortiedr/1.18.0/

@elastic-vault-github-plugin-prod

Package fortinet_fortigate - 1.31.0 containing this change is available at https://epr.elastic.co/package/fortinet_fortigate/1.31.0/

@andrewkroh andrewkroh added Integration:qnap_nas QNAP NAS (Community supported) Integration:syslog_router Syslog Router Integration:osquery Osquery Logs Integration:cef Common Event Format (CEF) Integration:stormshield StormShield SNS Integration:checkpoint Check Point Integration:watchguard_firebox WatchGuard Firebox Integration:fortinet_fortimail Fortinet FortiMail Integration:fortinet_fortiedr Fortinet FortiEDR Logs Integration:cisco_aironet Cisco Aironet (Community supported) Integration:sophos Sophos Integration:arista_ngfw Arista NG Firewall (Community supported) Integration:cisco_nexus Cisco Nexus Integration:fortinet_fortigate Fortinet FortiGate Firewall Logs Integration:citrix_waf Citrix Web App Firewall Integration:cisco_ios Cisco IOS Integration:tcp Custom TCP Logs Integration:iptables Iptables Integration:modsecurity ModSecurity Audit (Community supported) Integration:udp Custom UDP Logs Integration:proxysg Broadcom ProxySG Integration:netflow NetFlow Records Integration:fortinet_fortiproxy Fortinet FortiProxy Integration:fortinet_fortimanager Fortinet FortiManager Logs Integration:sonicwall_firewall SonicWall Firewall Integration:zeek Zeek Integration:imperva Imperva Integration:pfsense pfSense (Community supported) Integration:cisco_asa Cisco ASA labels Mar 13, 2025
flexitrev pushed a commit that referenced this pull request Mar 20, 2025
- Support stack 9.0 in integrations owned by deployment and devices
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request Integration:arista_ngfw Arista NG Firewall (Community supported) Integration:cef Common Event Format (CEF) Integration:checkpoint Check Point Integration:cisco_aironet Cisco Aironet (Community supported) Integration:cisco_asa Cisco ASA Integration:cisco_ftd Cisco FTD Integration:cisco_ios Cisco IOS Integration:cisco_ise Cisco ISE Integration:cisco_nexus Cisco Nexus Integration:cisco_secure_email_gateway Cisco Secure Email Gateway Integration:citrix_waf Citrix Web App Firewall Integration:fortinet_fortiedr Fortinet FortiEDR Logs Integration:fortinet_fortigate Fortinet FortiGate Firewall Logs Integration:fortinet_fortimail Fortinet FortiMail Integration:fortinet_fortimanager Fortinet FortiManager Logs Integration:fortinet_fortiproxy Fortinet FortiProxy Integration:goflow2 GoFlow2 logs (Community supported) Integration:hashicorp_vault Hashicorp Vault Integration:imperva Imperva Integration:iptables Iptables Integration:juniper_srx Juniper SRX Integration:modsecurity ModSecurity Audit (Community supported) Integration:netflow NetFlow Records Integration:osquery Osquery Logs Integration:pfsense pfSense (Community supported) Integration:proxysg Broadcom ProxySG Integration:qnap_nas QNAP NAS (Community supported) Integration:snort Snort Integration:sonicwall_firewall SonicWall Firewall Integration:sophos Sophos Integration:squid Squid Proxy Integration:stormshield StormShield SNS Integration:suricata Suricata Integration:syslog_router Syslog Router Integration:tcp Custom TCP Logs Integration:tetragon Cilium Tetragon Integration:udp Custom UDP Logs Integration:watchguard_firebox WatchGuard Firebox Integration:zeek Zeek Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Add stack 9.0 support to deployment and devices integrations
4 participants