all: migrate ssi packages to ecs@mappings - #10135
Conversation
There was a problem hiding this comment.
From a user perspective, do you think this second sentence is confusing? Maybe we should mention the ecs@mappings component template in some way. Like
Removed ECS field definitions that have been made redundant by the
ecs@mappingscomponent template.
There was a problem hiding this comment.
That seems reasonable.
There was a problem hiding this comment.
🚀 Benchmarks reportTo see the full report comment with |
09c8746 to
3e06b13
Compare
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
|
Correction: actually not an issue since we're not importing them now. They should just be there, presumably for transform destination indexes as well as data streams. |
Update: Transform destination indexes don't get the ECS dynamic templates that data streams get. This PR doesn't remove the manual definitions in transforms, so it still works (checked for ti_opencti). |
chrisberkhout
left a comment
There was a problem hiding this comment.
I looked at the full diffs for 4 or 5 integrations and checked out the impact on transforms in detail for ti_opencti. All looks good.
The conditions.kibana.version in the package manifest changed from ^8.12.0 to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@v0.0.0-20240617213809-014b35dfe4c9 -ecs-version=8.11.0 -ecs-git-ref=git@v8.11.0 -drop-import-mappings -kibana-version=^8.13.0 -pr=10135 -fields-yml-drop-ecs packages/1password
The conditions.kibana.version in the package manifest changed from ^8.12.0 to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@v0.0.0-20240617213809-014b35dfe4c9 -ecs-version=8.11.0 -ecs-git-ref=git@v8.11.0 -drop-import-mappings -kibana-version=^8.13.0 -pr=10135 -fields-yml-drop-ecs packages/akamai
Removed import_mappings. The conditions.kibana.version in the package manifest changed from ^8.12.0 to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@v0.0.0-20240617213809-014b35dfe4c9 -ecs-version=8.11.0 -ecs-git-ref=git@v8.11.0 -drop-import-mappings -kibana-version=^8.13.0 -pr=10135 -fields-yml-drop-ecs packages/amazon_security_lake
The conditions.kibana.version in the package manifest changed from ^8.12.0 to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@v0.0.0-20240617213809-014b35dfe4c9 -ecs-version=8.11.0 -ecs-git-ref=git@v8.11.0 -drop-import-mappings -kibana-version=^8.13.0 -pr=10135 -fields-yml-drop-ecs packages/atlassian_bitbucket
The conditions.kibana.version in the package manifest changed from ^8.12.0 to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@v0.0.0-20240617213809-014b35dfe4c9 -ecs-version=8.11.0 -ecs-git-ref=git@v8.11.0 -drop-import-mappings -kibana-version=^8.13.0 -pr=10135 -fields-yml-drop-ecs packages/atlassian_confluence
The conditions.kibana.version in the package manifest changed from ^8.12.0 to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@v0.0.0-20240617213809-014b35dfe4c9 -ecs-version=8.11.0 -ecs-git-ref=git@v8.11.0 -drop-import-mappings -kibana-version=^8.13.0 -pr=10135 -fields-yml-drop-ecs packages/atlassian_jira
The conditions.kibana.version in the package manifest changed from ^8.12.0 to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@v0.0.0-20240617213809-014b35dfe4c9 -ecs-version=8.11.0 -ecs-git-ref=git@v8.11.0 -drop-import-mappings -kibana-version=^8.13.0 -pr=10135 -fields-yml-drop-ecs packages/auth0
The conditions.kibana.version in the package manifest changed from ^8.12.0 to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@v0.0.0-20240617213809-014b35dfe4c9 -ecs-version=8.11.0 -ecs-git-ref=git@v8.11.0 -drop-import-mappings -kibana-version=^8.13.0 -pr=10135 -fields-yml-drop-ecs packages/aws_bedrock
Removed import_mappings. The conditions.kibana.version in the package manifest changed from ^8.12.0 to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template. The ecs.version in sample_event.json files was changed to 8.11.0. Previously sample_event.json files contained 8.0.0. [git-generate] go run github.com/andrewkroh/go-examples/ecs-update@v0.0.0-20240617213809-014b35dfe4c9 -ecs-version=8.11.0 -ecs-git-ref=git@v8.11.0 -drop-import-mappings -kibana-version=^8.13.0 -pr=10135 -fields-yml-drop-ecs packages/azure_blob_storage
|
Package panw_cortex_xdr - 1.27.0 containing this change is available at https://epr.elastic.co/search?package=panw_cortex_xdr |
|
Package ping_one - 1.16.0 containing this change is available at https://epr.elastic.co/search?package=ping_one |
|
Package pps - 0.1.0 containing this change is available at https://epr.elastic.co/search?package=pps |
|
Package prisma_cloud - 1.3.0 containing this change is available at https://epr.elastic.co/search?package=prisma_cloud |
|
Package proofpoint_tap - 1.22.0 containing this change is available at https://epr.elastic.co/search?package=proofpoint_tap |
|
Package pulse_connect_secure - 2.1.0 containing this change is available at https://epr.elastic.co/search?package=pulse_connect_secure |
|
Package qualys_vmdr - 3.3.0 containing this change is available at https://epr.elastic.co/search?package=qualys_vmdr |
|
Package rapid7_insightvm - 1.12.0 containing this change is available at https://epr.elastic.co/search?package=rapid7_insightvm |
|
Package santa - 3.18.0 containing this change is available at https://epr.elastic.co/search?package=santa |
Proposed commit message
Checklist
changelog.ymlfile.Author's Checklist
How to test this PR locally
Related issues
Screenshots