[Suricata] Add Observer Metadata - #6985
Conversation
…akoWish/integrations into suricata_add_observer_metadata
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
…akoWish/integrations into suricata_add_observer_metadata
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
…akoWish/integrations into suricata_add_observer_metadata
…akoWish/integrations into suricata_add_observer_metadata
…akoWish/integrations into suricata_add_observer_metadata
|
/test |
🌐 Coverage report
|
…akoWish/integrations into suricata_add_observer_metadata
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
|
@efd6 , Would you mind kicking off a |
|
/test |
Co-authored-by: Dan Kortschak <90160302+efd6@users.noreply.github.com>
|
Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as |
|
/test |
|
You'll need to run |
…akoWish/integrations into suricata_add_observer_metadata
I usually do, but looks like I didn't on this one. Done. |
|
/test |
|
Package suricata - 2.18.0 containing this change is available at https://epr.elastic.co/search?package=suricata |
Type of change
What does this PR do?
The Suricata integration currently supports removing
host.*fields if "forwarded" is intags, but it does not currently populate theobserver.*fields. This PR adds that functionality.Checklist
changelog.ymlfile.manifest.ymlfile.Author's Checklist
observer.*fieldsRelated issues
observer.*Fields for Integration #6984