Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
960 commits
Select commit Hold shift + click to select a range
af6c1ae
[aws] Add configuration option for TLD for httpjson inputs (#8027)
kgeller Oct 2, 2023
478786b
Bump github.com/elastic/elastic-package from 0.87.1 to 0.88.0 (#8039)
dependabot[bot] Oct 2, 2023
dced09c
[Cloud Security] Add GCP rule templates (#8007)
orouz Oct 2, 2023
a818815
[synthetics] Update synthetics minor for 8.11 changes (#8045)
emilioalvap Oct 2, 2023
67dd2e2
[azure_frontdoor] Fix Azure frontdoor preserve original event (#7464)
nicpenning Oct 2, 2023
1fe6dae
[Barracuda_WAF] Change the package name (#7735)
vinit-chauhan Oct 3, 2023
cfbe348
[Suricata] Add Observer Metadata (#6985)
MakoWish Oct 3, 2023
32ebef3
cisco_asa,cisco_ftd,juniper_srx: remove redundant regular expression …
efd6 Oct 3, 2023
39190a9
[Azure][Storage_account] Add dimension to the storage account datastr…
ritalwar Oct 3, 2023
7142b33
[Azure Storage Account] Add metric_type metadata to the storage_accou…
ritalwar Oct 3, 2023
78cc259
[sei packages] Undefined log.file.* fields breaking tests for filestr…
bhapas Oct 3, 2023
4d984df
[cloud_security_posture] Allow multiple installations (#8043)
amirbenun Oct 3, 2023
0b9c00e
[wiz] Initial Release for Wiz (#7839)
mohitjha-elastic Oct 3, 2023
cd938bd
[Security Rules] Update security rules package to v8.10.4-beta.1 (#8076)
terrancedejesus Oct 3, 2023
cb4d7ca
[ECS] Updating journald to ECS 8.10 for new `process.thread.capabilit…
kgeller Oct 3, 2023
63e43da
forgerock: use dynamic mappings for object fields (#8056)
efd6 Oct 3, 2023
70a8199
[zeek] - Modified field definitions to use ECS (#8062)
andrewkroh Oct 3, 2023
26c62d5
[Cisco ISE] Add event.code based on cisco_ise.log.message.code (#8071)
philippkahr Oct 4, 2023
b8b4510
[cloud_security_posture] Add Azure rule templates (#8042)
jeniawhite Oct 4, 2023
ad56187
[Cloud Security] Bump integration version (#8084)
orouz Oct 4, 2023
2b9b28b
[obs-cloud-monitoring] Add undefined log.file.* fields breaking tests…
bhapas Oct 4, 2023
edc0b18
[O11y][Prometheus] Migrate Prometheus Server Overview dashboard to le…
rajvi-patel-22 Oct 4, 2023
e9ce6ee
[Cisco ASA] Fix the processing of the protocol field for 313005 (#8089)
chemamartinez Oct 4, 2023
6a0f662
[m365_defender] Fix duplicate event.original field (#8090)
bhapas Oct 4, 2023
e199608
[Beaconing] Packaging Network Beaconing Detection (#7418)
sodhikirti07 Oct 4, 2023
cc5374c
zeek: use dynamic mapping for object fields (#8080)
efd6 Oct 4, 2023
6719d69
[elastic_agent] - Cleanup fields.yml issues (#8079)
andrewkroh Oct 4, 2023
41d2aa1
[box_events] - Clean-up field definitions (#8097)
andrewkroh Oct 5, 2023
97c0ec8
[O11y][Containerd Metrics] Migrate Containerd Overview Dashboard to l…
kush-elastic Oct 5, 2023
9a6fcf2
Migrate Logs Overview dashboard visualizations to lens (#8086)
rajvi-patel-22 Oct 5, 2023
4becaf6
[Golang] Migrate to GA (#7651)
harnish-crest-data Oct 5, 2023
3593b7b
Add Bot fields to HTTP events in Cloudflare integrations (#8093)
chemamartinez Oct 5, 2023
ab65107
[Olly] [AWS] Update Billing Overview dashboard (#7659)
milan-elastic Oct 5, 2023
5404dfc
[O11y][Apache Spark] Update MBean for driver datastream (#8061)
harnish-crest-data Oct 5, 2023
6c34861
Add undefined log.file.* fields breaking tests for filestream inputs …
bhapas Oct 5, 2023
bb4fbfa
[system] - Cleanup fields.yml files (#8100)
andrewkroh Oct 5, 2023
a4a542b
[Synthetics] Break out synthetics dashboard integration with adhoc da…
emilioalvap Oct 5, 2023
cd7862a
[windows] - Cleanup fields.yml files (#8099)
andrewkroh Oct 5, 2023
4ee9696
[TrendMicro VisionOne] Fix Detection API TMV1-Query header (#8083)
kcreddy Oct 6, 2023
647768b
[O11y][CouchDB] Remove forwarded tag from metrics data streams (#7826)
harnish-crest-data Oct 9, 2023
5366772
[O11y][STAN] Fix reference error in Channel Overview dashboard (#7959)
rajvi-patel-22 Oct 9, 2023
cd91359
[O11y][IBM MQ] Remove forwarded tag from metrics data streams (#7828)
harnish-crest-data Oct 9, 2023
53d0d09
[O11y][Websphere Application Server] Remove forwarded tag from metric…
harnish-crest-data Oct 9, 2023
b582e43
update changelog.yml (#7827)
harnish-crest-data Oct 9, 2023
8f416b1
[O11y][Couchbase] Remove forwarded tag from metrics data streams (#7825)
harnish-crest-data Oct 9, 2023
3b4d0d9
[PHP-FPM] Migrate to GA (#7648)
harnish-crest-data Oct 9, 2023
28bb6da
[O11y][ActiveMQ] Remove forwarded tag from metrics data streams (#7823)
harnish-crest-data Oct 9, 2023
27cc608
Added 2x more test logs (#8136)
philippkahr Oct 9, 2023
7dd75d0
[System] rework metric dashboards (#6743)
drewdaemon Oct 9, 2023
85b68c9
[AWS] Add the ignore_missing and null checks to rename processor (#7933)
ishleenk17 Oct 10, 2023
f016fa0
[O11y][NATS] Migrate Metrics Overview dashboard visualizations to len…
rajvi-patel-22 Oct 10, 2023
8b54515
[O11y][Traefik] Add dimension fields for health datastream (#7767)
harnish-crest-data Oct 10, 2023
913c482
[O11y][Traefik] Add metric_type for health datastream (#7768)
harnish-crest-data Oct 10, 2023
4a4e900
[O11y][Traefik] Enable time series data stream for the health (#7781)
harnish-crest-data Oct 10, 2023
e089669
[Logstash] Add CEL native data collection, and dashboards for Pipelin…
robbavey Oct 10, 2023
851f8a6
[Cloudflare] Add option to include Bot fields in API requests (#8155)
chemamartinez Oct 10, 2023
8238506
[panw] Adding traffic and threat performance benchmarks (#7545)
ebeahan Oct 10, 2023
ae728fa
[NATS] Add connection data stream dimensions (#7739)
Oct 10, 2023
233c4b0
Add routing rules for cloudfront logs, elb logs and s3access logs (#7…
Oct 10, 2023
e652ce7
[O11y][Logs Nginx Ingress Controller] Migrate Nginx Ingress Controlle…
kush-elastic Oct 11, 2023
207e0ce
[O11y][Logs Nginx Ingress Controller] Migrate Nginx Ingress Controlle…
kush-elastic Oct 11, 2023
f019c87
[O11y] [Springboot] support tags to gc, memory and threading datastre…
milan-elastic Oct 11, 2023
c68cafb
[Hashicorp Vault] Add metric_type mapping to metrics datastream (#8132)
agithomas Oct 11, 2023
67126ad
[HA Proxy] Fix incorrect mapping of source.address field in stat data…
agithomas Oct 11, 2023
727ed61
[Zookeeper] Added dimensions mapping to Zookeeper connection datastre…
agithomas Oct 11, 2023
d4001a5
Reference ecs 8.10 in cloud-defend package (#8151)
nicholasberlin Oct 11, 2023
acde9a3
Added dimension mapping to zookeeper mntr datastream (#8069)
agithomas Oct 11, 2023
701558e
[Zookeeper] Added dimensions mapping to server datastream (#8081)
agithomas Oct 11, 2023
059c806
[amazon_security_lake] Add data subscriber steps in readme (#8113)
janvi-elastic Oct 11, 2023
763d7f4
[Cloud Security] Azure: Link to 8.11 ARM template (#8092)
orestisfl Oct 11, 2023
cd0a5ec
Zookeeper TSDB Enablement (#8104)
agithomas Oct 12, 2023
3baf029
[TI_OTX] Add IOC expiration support with new datastream (#7530)
kcreddy Oct 12, 2023
1e8f627
[apache_tomcat] - Migrate to package-spec v3 (#8159)
shmsr Oct 12, 2023
06dd24f
Update elastic-package to use Package Spec 3.0.0-rc1 and fix v3 packa…
jsoriano Oct 12, 2023
61dc98b
Bump golang.org/x/net from 0.15.0 to 0.17.0 (#8168)
dependabot[bot] Oct 12, 2023
b0cb323
[O11y][Oracle WebLogic] Add dimension fields for deployed_application…
harnish-crest-data Oct 12, 2023
5e23a62
[apache_tomcat] Quote keys with dots in test config files (#8174)
jsoriano Oct 12, 2023
d063080
[integrations][Cisco Meraki] - Removed experimental release tags from…
ShourieG Oct 12, 2023
af9ab41
[integrations] - Improve docs & fix minor bugs for Microsoft exchange…
ShourieG Oct 12, 2023
2f3a9b9
[NATS] Add connection data stream metric types (#7740)
Oct 12, 2023
aeed9aa
[O11y][Oracle WebLogic] Add metric_type for deployed_application data…
harnish-crest-data Oct 12, 2023
92265bc
[O11y][Apache Spark] Add dimension mapping for application datastream…
harnish-crest-data Oct 12, 2023
bf4d09b
[NATS] Add connections data stream dimensions and metric_type (#7741)
Oct 12, 2023
c622d91
added metrics data streams to fleet_server (#8145)
juliaElastic Oct 12, 2023
2568e0d
[O11y][Oracle WebLogic] Add dimension fields for threadpool datastrea…
harnish-crest-data Oct 12, 2023
3e6d75e
[O11y][Apache Spark] Add metric_type for application data stream (#7795)
harnish-crest-data Oct 12, 2023
39ffbfe
[O11y][Apache Spark] Add dimension mapping for driver datastream (#8111)
harnish-crest-data Oct 12, 2023
052f682
[NATS] Add route data stream dimensions (#7742)
Oct 12, 2023
ea5ec9b
[O11y][Oracle WebLogic] Add metric_type for threadpool datastream (#7…
harnish-crest-data Oct 12, 2023
6168b22
[NATS] Add route data stream metric types (#7743)
Oct 12, 2023
68a65d5
Removing detection rules from the `lmd` package (#7901)
ajosh0504 Oct 12, 2023
06e794c
[NATS] Add stats data stream dimensions (#7746)
Oct 12, 2023
d49f2c2
Removing detection rules from the `dga` package (#7902)
ajosh0504 Oct 12, 2023
78b097f
Removing detection rules from the `problemchild` package (#7903)
ajosh0504 Oct 12, 2023
aa6d714
Removing detection rules from the `ded` package (#7947)
ajosh0504 Oct 12, 2023
eb62107
[NATS] Add stats data stream metric types (#7747)
Oct 12, 2023
557e492
[NATS] Add subscriptions data stream dimensions (#7748)
Oct 12, 2023
5f1f213
[NATS] Add subscriptions data stream metric types (#7749)
Oct 12, 2023
16b2c29
ref 8.10 tag instead of branch (#8167)
nicholasberlin Oct 12, 2023
d7b9c19
fix linting (#8180)
ebeahan Oct 12, 2023
a754869
infoblox_bloxone_ddi: fix handling of options fields (#8082)
efd6 Oct 12, 2023
620f766
[O11y][Apache Spark] Add metric type mapping for driver datastream (#…
harnish-crest-data Oct 13, 2023
42f6631
[O11y][Apache Spark] Add dimension mapping for Executor datastream (#…
harnish-crest-data Oct 13, 2023
a840b52
[O11y][Apache Spark] Add metric_type for executor data stream (#7831)
harnish-crest-data Oct 13, 2023
555a462
Fix missing request in pipeline (#8160)
kcreddy Oct 13, 2023
8256332
[O11y][Apache Spark] Add dimension mapping for Node datastream (#7996)
harnish-crest-data Oct 13, 2023
56bbebf
[entityanalytics_entra_id] Add device dataset in Microsoft Entra ID (…
brijesh-elastic Oct 13, 2023
213a312
Run daily job with 8.11 SNAPSHOT (#8181)
ebeahan Oct 13, 2023
f416295
[O11y][Apache Spark] Add metric_type for node data stream (#7794)
harnish-crest-data Oct 13, 2023
5d4eaaa
[tenable_io] Update Interval and Initial Interval of Asset, Vulnerabi…
mohitjha-elastic Oct 13, 2023
ef7cc5f
[Cisco ASA] Support 113015 event and hidden username value (#8182)
chemamartinez Oct 13, 2023
c493cf1
[Wiz] Added Dashboards for all the Data Streams (#8154)
mohitjha-elastic Oct 13, 2023
2a60eeb
[System] Convert all legacy visualizations (#8139)
drewdaemon Oct 13, 2023
bb6c604
[Data Exfiltration Detection] Update files to add Serverless support …
sodhikirti07 Oct 13, 2023
c1096db
[ProblemChild] Update files to add Serverless support to the package …
sodhikirti07 Oct 13, 2023
469ded1
[Security Rules] Update security rules package to v8.11.1-beta.1 (#8198)
terrancedejesus Oct 13, 2023
d38087c
[Security Rules] Update security rules package to v8.11.1 (#8202)
terrancedejesus Oct 13, 2023
093cf15
Infoblox_nios: add client geoip and registered_domain processors to d…
philippkahr Oct 15, 2023
4583d61
[O11y][Oracle WebLogic] Enable time series data streams for the deplo…
harnish-crest-data Oct 16, 2023
43088cb
[integrations][Cloudflare Logpull] - Fixed invalid time range issue (…
ShourieG Oct 16, 2023
c9e4188
Update (most) obs-cloud-monitoring owned packages to format_version 3…
tommyers-elastic Oct 16, 2023
3e15a1d
Update `azure` package to format_version 3.0.0 (#8050)
tommyers-elastic Oct 16, 2023
25d4bc9
slack: fix handling of oldest parameter when paginating (#8169)
efd6 Oct 16, 2023
befdc5c
[Cloud Security] Update manifest format_version to 3.0.0 for cloud_se…
maxcold Oct 16, 2023
19d25db
[Cloud Security] add securty capability to Cloud Defend package so it…
maxcold Oct 16, 2023
1f4cad9
[Lateral Movement Detection] Update files to add Serverless support t…
sodhikirti07 Oct 16, 2023
96d2416
[ti_opencti] OpenCTI integration (#7385)
chrisberkhout Oct 16, 2023
07173fd
[NATS] Add routes data stream dimensions and metric types (#7744)
Oct 16, 2023
4c455e7
[O11y][Apache Spark] Enable time series data stream for the applicati…
harnish-crest-data Oct 17, 2023
bb52565
[O11y][Apache Spark] Add filters in the visualizations (#8117)
harnish-crest-data Oct 17, 2023
0f5d3e0
[Cloud Security] Add Elastic-specific tags in CloudFormation (#8226)
orestisfl Oct 17, 2023
f40f387
[salesforce] Update package to format_version 3.0.0 (#8215)
tommyers-elastic Oct 17, 2023
1c150f8
[Cloud Security] Assign default GCP account type (#8228)
jeniawhite Oct 17, 2023
ea11ce8
[Logstash] Update manifest format_version to 3.0.0 for logstash integ…
robbavey Oct 17, 2023
6a34603
Add tags for aws package resources (#8214)
mrodm Oct 17, 2023
cc7f38a
[system][process] Enable tsdb for process datastream (#7672)
tetianakravchenko Oct 17, 2023
39eea2a
[azure_application_insights] [app_state] Add dimensions, metric_type …
Oct 17, 2023
ffe9c35
[O11y][Apache Tomcat] Add TSDB enablement for request and cache data …
harnish-crest-data Oct 18, 2023
d63214f
Migrate obs-infraobs-integrations to package-spec v3 #1 (#8170)
shmsr Oct 18, 2023
225555f
Migrate obs-infraobs-integrations to package-spec v3 #4 (#8216)
shmsr Oct 18, 2023
683d9a2
[HA Proxy] Add dimension fields for stat datastream (#7323)
agithomas Oct 18, 2023
127b2a0
[PANW] PAN-OS v11 Support (#8178)
kgeller Oct 18, 2023
27ca1d5
[HA Proxy ]Corrected incorrect aggregation function used in visualisa…
agithomas Oct 18, 2023
4afdf73
[Azure][Storage_account] Enable TSDB (#8064)
ritalwar Oct 19, 2023
0ac9fd2
[Cloud Security] Base CloudFormation url only on version (#8246)
orestisfl Oct 19, 2023
6445a75
Migrate obs-infraobs-integrations to package-spec v3 #2 (#8171)
shmsr Oct 19, 2023
4725c60
Bump github.com/elastic/elastic-package from 0.89.2 to 0.90.0 (#8233)
dependabot[bot] Oct 19, 2023
22b5c72
[system] Adds `tags.yml` file so they appear under the Security Solut…
marc-gr Oct 19, 2023
2586079
Added field `winlog.event_data.EnabledPrivilegeList` (#8230)
leehinman Oct 19, 2023
399ac66
update generator configs content to v0.7.0 format (#8247)
Oct 20, 2023
f70d984
[Cisco ASA] Support patterns with SGT tag:name as username (#8205)
kcreddy Oct 23, 2023
1e027ba
[O11y][Apache] Migrate `Uptime` metric visualization to lens (#8173)
rajvi-patel-22 Oct 23, 2023
4223de7
[O11y][K8] Migrate `Jobs` dashboard visualizations to lens (#8262)
rajvi-patel-22 Oct 23, 2023
29d3d56
[O11y][Hadoop] Update human readable format of metric visualization (…
rajvi-patel-22 Oct 23, 2023
f6cc2d1
[Prisma Cloud] Initial Release for Prisma Cloud (#8135)
mohitjha-elastic Oct 23, 2023
25849be
Add `dimension` field previously missed during package-spec v3 migrat…
shmsr Oct 23, 2023
aaf1a2c
Support additional log format in Apache (#8249)
ishleenk17 Oct 23, 2023
95d7eea
[Apache Spark] Migrate to GA (#7650)
harnish-crest-data Oct 23, 2023
7897c77
[O11y][K8s] Migrate `StatefulSets` dashboard visualizations to lens (…
rajvi-patel-22 Oct 23, 2023
95f7a34
[Imperva] Replace RSA2ELK with Syslog integration for Imperva Secures…
mohitjha-elastic Oct 23, 2023
908c564
[O11y][Stan] Migrate Channel Overview Metrics Dashboard Visualization…
milan-elastic Oct 23, 2023
2440a0b
[O11y][Stan] Migrate Logs Overview Dashboard Visualizations to Lens (…
milan-elastic Oct 23, 2023
a89d7cf
[O11y][K8] Migrate DaemonSets dashboard visualizations to lens (#8266)
kush-elastic Oct 23, 2023
bb3149c
Bump github.com/elastic/elastic-package from 0.90.0 to 0.91.0 (#8272)
dependabot[bot] Oct 23, 2023
b9a6ebd
[sentinel_one] Add support for missing missing_permissions field (#8270)
mohitjha-elastic Oct 23, 2023
26c8cb3
windows: make pipeline routing robust to channel letter case (#8242)
efd6 Oct 23, 2023
5f8f554
[ti_rapid7_threat_command] Fix required stack capabilities (#8268)
jsoriano Oct 24, 2023
91f905e
google_workspace,infoblox_bloxone_ddi: fix documentation for initial …
efd6 Oct 24, 2023
ebd76ec
[sei] Add checks to avoid overriding event.original if present (#8269)
marc-gr Oct 24, 2023
993537b
Bump github.com/elastic/elastic-package from 0.91.0 to 0.91.1 (#8277)
dependabot[bot] Oct 24, 2023
a5d3cff
[Security Rules] Update security rules package to v8.11.2-beta.1 (#8282)
terrancedejesus Oct 24, 2023
469d921
[Security Rules] Update security rules package to v8.11.2 (#8288)
terrancedejesus Oct 24, 2023
dbe0025
TSDB enablement for HAProxy datastreams (#8224)
agithomas Oct 25, 2023
40b48e2
Dimension setting added to host.name in system package (#8261)
ishleenk17 Oct 25, 2023
18bf78a
Migrate obs-infraobs-integrations to package-spec v3 #5 (#8234)
shmsr Oct 25, 2023
487d594
[O11y][Metrics Windows] Migrate Windows Services Dashboard to lens (#…
kush-elastic Oct 25, 2023
da0fc7a
Migrate obs-infraobs-integrations to package-spec v3 #3 (#8203)
shmsr Oct 25, 2023
19ba187
[Cloudflare Logpush] Add non_aws_bucket_name option to AWS S3 input (…
chemamartinez Oct 25, 2023
51a09b1
[Hashicorp Vault] Added dimensions mapping and added missing label fi…
agithomas Oct 25, 2023
71cbd73
[UDP/TCP] Add reroute processor support (#8294)
P1llus Oct 25, 2023
a741c45
[symantec_edr_cloud] Initial release of the symantec edr cloud (#8267)
janvi-elastic Oct 25, 2023
90ce86e
[O11y][HAProxy] Migrate log data-stream visualizations to lens in kib…
rajvi-patel-22 Oct 26, 2023
ad1a9dc
[Postgresql] [Bugfix] create new field query_id field to replace quer…
agithomas Oct 26, 2023
1b9082e
[O11y][Redis] Update value format of `Top Slowest command` visualiza…
rajvi-patel-22 Oct 26, 2023
b5d6c9c
Bump google.golang.org/grpc from 1.57.0 to 1.57.1 (#8295)
dependabot[bot] Oct 26, 2023
8236557
[System] Add RFC 5424 support to Auth datastream (#8103)
kcreddy Oct 26, 2023
c856d61
[cloud_security_posture] GCP OrganizationId must be string (#8300)
amirbenun Oct 26, 2023
4a57b22
[HAProxy] Fix the Grok pattern for parsing TCP logs (#8255)
devamanv Oct 26, 2023
072996d
[aws] Remove unused aws.*.metrics.*.* and aws.s3.bucket.name (#8140)
Oct 26, 2023
6b21077
[NATS] Enable TSDB (#8243)
Oct 27, 2023
29ec02c
[O11y][K8s] Migrate `Cronjobs` dashboard visualizations to lens (#8263)
rajvi-patel-22 Oct 27, 2023
ab11988
[buildkite] Add new Buildkite pipelines to test packages with Serverl…
mrodm Oct 27, 2023
790e6a9
jumpcloud: map jumpcloud.event.changes as flattened (#8298)
efd6 Oct 27, 2023
19da299
[qualys_vmdr] Handle Invalid Input Parameter for Knowledge Base Data …
mohitjha-elastic Oct 27, 2023
9f1728a
[Universal Profiling Collector]: Add agent_metrics (#8189)
florianl Oct 27, 2023
1688326
qualys_vmdr: add request tracer logging (#8290)
efd6 Oct 27, 2023
46f291b
[STAN] Add channels data stream dimensions (#7863)
Oct 29, 2023
f7edc69
[STAN] Add channels data stream metric types (#7862)
Oct 29, 2023
c5411cf
[STAN] Add stats data stream dimensions (#7864)
Oct 30, 2023
3e58a9a
[STAN] Add stats data stream metric types (#7861)
Oct 30, 2023
6f9073c
[elastic_agent] add data_streams for Universal Profiling services (#8…
florianl Oct 30, 2023
798d9ce
modsecurity: add missing destination.{as,geo}.* field definitions and…
efd6 Oct 30, 2023
fde9698
[apache_tomcat]: Make parser configurable for catalina and localhost …
ishleenk17 Oct 30, 2023
e17b11b
[Fortinet] Add support for 7.4 events (#8036)
marc-gr Oct 30, 2023
359415a
[IIS] Add regex and tests for Exchange logs (#7559)
LaZyDK Oct 30, 2023
90ca120
[Hashicorp Vault] TSDB enablement for Hashicorp vault (#8302)
agithomas Oct 30, 2023
5a55399
[STAN] Add subscriptions data stream dimensions (#7865)
Oct 30, 2023
f7020cf
[STAN] Add subscriptions data stream metric types (#7860)
Oct 30, 2023
a8fb41c
[winlog] Convert to an input package. (#8010)
marc-gr Oct 30, 2023
adaabb0
[lmd] Update unattended flag (#8320)
susan-shu-c Oct 30, 2023
74d2a45
[docs] Update IIS README to use documentation guidelines (#8241)
colleenmcginnis Oct 30, 2023
ae2f82c
[docs] Update MSSQL README to use documentation guidelines (#8240)
colleenmcginnis Oct 30, 2023
d06a60e
[vsphere]: Update README with limitations in Virtual Machine metrics …
ishleenk17 Oct 31, 2023
d3f699b
[Azure Logs] Rebrand azure spring cloud logs to azure spring apps log…
muthu-mps Oct 31, 2023
31ae0b3
[AWS][Security Hub] Update Donut charts with Pie (#8332)
kush-elastic Oct 31, 2023
9c1dac6
[O11y][K8] Migrate Deployments dashboard visualizations to lens (#8265)
kush-elastic Oct 31, 2023
4640cc3
[cisco_secure_email_gateway] Support New Format for Mail Category of …
mohitjha-elastic Oct 31, 2023
4446b87
cisco_meraki,zscalar_zpa: fix field mappings and definitions (#8341)
efd6 Oct 31, 2023
a43c895
[System] Fix indentation of tags inside syslog datastream (#8345)
kcreddy Oct 31, 2023
ca6dc49
[Kubernetes] Add state namespace datastream (#8329)
constanca-m Oct 31, 2023
4013226
[Logstash] Add plugin specific drilldown dashboards (#8258)
robbavey Nov 1, 2023
698589a
system,windows: fix UAC attribute bit table (#8361)
efd6 Nov 1, 2023
c3fcfbf
[bitwarden] Add support for the member data stream (#8352)
brijesh-elastic Nov 1, 2023
bb36819
[crowdstrike] Prefer ImageFileName for the value of process.executabl…
chrisberkhout Nov 1, 2023
faa1e0e
[Cisco ASA] Fix GROK adding support to usernames ending with "$" (#8362)
kcreddy Nov 1, 2023
4c63515
[O11y][Apache Tomcat] Fix pipeline test and rename `header_forwarder`…
harnish-crest-data Nov 1, 2023
ba8127f
Update k8s version to 1.28 (#8349)
constanca-m Nov 1, 2023
5dc20b6
CloudFormation version hardening (#8366)
moukoublen Nov 1, 2023
9758f9c
[SpringBoot] Migrate to GA (#8223)
milan-elastic Nov 1, 2023
bb17ebd
[docs] Update MSSQL README (#8360)
colleenmcginnis Nov 1, 2023
86950cb
Extract user.name from user.email (#8368)
bhapas Nov 2, 2023
b93b686
[ti_recordedfuture] Fix the parsing of providers info from evidence f…
chemamartinez Nov 2, 2023
5d5aec7
[Cisco Meraki] Simplify ipflows pipeline to cover ICMP events (#8354)
chemamartinez Nov 2, 2023
31da033
[microsoft_dhcp] map DHCP client to source.* and server to host.* (#…
xtruthx Nov 2, 2023
d28782e
[O11y][Azure Application Insight] App state overview Lens Migration (…
milan-elastic Nov 3, 2023
9a72007
[sentinel_one_cloud_funnel] Add system test for aws-s3 input (#8386)
bhapas Nov 3, 2023
7d1faf9
o365: add fallback for missing startTime (#8374)
efd6 Nov 3, 2023
0517543
[cisco_meraki] Fix handling of security events without dhost and with…
marc-gr Nov 3, 2023
5a64b09
[O11y][Stan] Migrate `Client IP Count Timeline` visualization to lens…
harnish-crest-data Nov 3, 2023
bcc84a8
[ci] Fix Jenkinsfile to use the json files for pipeline benchmarks re…
marc-gr Nov 3, 2023
0884843
[O11y][NATS] Migrate `Client IP Count Timeline` visualization to lens…
harnish-crest-data Nov 3, 2023
7a355ba
Add aws-s3 system tests and add missing fields (#8392)
bhapas Nov 3, 2023
474a599
[cisco_umbrella] Add system tests for aws-s3 input and fix fields (#8…
bhapas Nov 3, 2023
fd8056d
Bump github.com/elastic/package-registry from 1.21.0 to 1.22.0 (#8387)
dependabot[bot] Nov 3, 2023
62d9d0b
Updated files per PR 8222
tychon1 Nov 13, 2023
c270a2c
fixes for system tests
taylor-swanson Nov 13, 2023
c78c092
additional fixes
taylor-swanson Nov 13, 2023
12ad959
Updated Fixes from ES testing
tychon1 Nov 14, 2023
7db7690
Merge branch 'Arp-Demonstration' of https://github.com/joeperuzzi/int…
tychon1 Nov 14, 2023
631a934
Updated test Data & added docker-compose.yml
tychon1 Nov 15, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
54 changes: 54 additions & 0 deletions .buildkite/hooks/post-checkout
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
#!/bin/bash

set -euo pipefail

checkout_merge() {
local target_branch=$1
local pr_commit=$2
local merge_branch=$3

if [[ -z "${target_branch}" ]]; then
echo "No pull request target branch"
exit 1
fi

git fetch -v origin "${target_branch}"
git checkout FETCH_HEAD
echo "Current branch: $(git rev-parse --abbrev-ref HEAD)"

# create temporal branch to merge the PR with the target branch
git checkout -b ${merge_branch}
echo "New branch created: $(git rev-parse --abbrev-ref HEAD)"

# set author identity so it can be run git merge
git config user.name "github-merged-pr-post-checkout"
git config user.email "auto-merge@buildkite"

git merge --no-edit "${BUILDKITE_COMMIT}" || {
local merge_result=$?
echo "Merge failed: ${merge_result}"
git merge --abort
exit ${merge_result}
}
}

pull_request="${BUILDKITE_PULL_REQUEST:-false}"

if [[ "${pull_request}" == "false" ]]; then
echo "Not a pull request, skipping"
exit 0
fi

TARGET_BRANCH="${BUILDKITE_PULL_REQUEST_BASE_BRANCH:-master}"
PR_COMMIT="${BUILDKITE_COMMIT}"
PR_ID=${BUILDKITE_PULL_REQUEST}
MERGE_BRANCH="pr_merge_${PR_ID}"

checkout_merge "${TARGET_BRANCH}" "${PR_COMMIT}" "${MERGE_BRANCH}"

echo "Commit information"

git --no-pager log --format=%B -n 1

# Ensure buildkite groups are rendered
echo ""
78 changes: 78 additions & 0 deletions .buildkite/hooks/pre-command
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
#!/bin/bash

source .buildkite/scripts/common.sh

set -euo pipefail

# Avoid any pager when running git commands
git config --global core.pager 'cat'

export UPLOAD_SAFE_LOGS=${UPLOAD_SAFE_LOGS:-"0"}
export BASE_DIR=$(pwd)
export GO_VERSION=$(cat .go-version)

export REPO_NAME=$(repo_name "${BUILDKITE_REPO}")
export TMP_FOLDER_TEMPLATE_BASE="tmp.${REPO_NAME}"
export TMP_FOLDER_TEMPLATE="${TMP_FOLDER_TEMPLATE_BASE}.XXXXXXXXX"

export REPO_BUILD_TAG="${REPO_NAME}/$(buildkite_pr_branch_build_id)"

JENKINS_API_TOKEN_PATH=kv/ci-shared/platform-ingest/jenkins_api_tokens
SIGNING_PACKAGES_GCS_CREDENTIALS_PATH=kv/ci-shared/platform-ingest/signing_packages_gcs_artifacts_credentials
PACKAGE_UPLOADER_GCS_CREDENTIALS_PATH=kv/ci-shared/platform-ingest/package_storage_uploader
PRIVATE_CI_GCS_CREDENTIALS_PATH=kv/ci-shared/platform-ingest/private_ci_artifacts_gcs_credentials

EC_TOKEN_PATH=kv/ci-shared/platform-ingest/platform-ingest-ec-qa
EC_DATA_PATH=secret/ci/elastic-integrations/ec_data

if [ -n "${ELASTIC_PACKAGE_LINKS_FILE_PATH+x}" ]; then
# first upload pipeline does not have the environment variables defined in the YAML
export ELASTIC_PACKAGE_LINKS_FILE_PATH=${BASE_DIR}/${ELASTIC_PACKAGE_LINKS_FILE_PATH}
fi

if [ ${BUILDKITE_PIPELINE_SLUG} == "integrations" ]; then
if [ ${BUILDKITE_STEP_KEY} == "publish-packages" ]; then
export JENKINS_USERNAME_SECRET=$(retry 5 vault kv get -field username ${JENKINS_API_TOKEN_PATH})
export JENKINS_HOST_SECRET=$(retry 5 vault kv get -field internal_ci_host ${JENKINS_API_TOKEN_PATH})
export JENKINS_TOKEN=$(retry 5 vault kv get -field internal_ci ${JENKINS_API_TOKEN_PATH})

# signing job
export SIGNING_PACKAGES_GCS_CREDENTIALS_SECRET=$(retry 5 vault kv get -field value ${SIGNING_PACKAGES_GCS_CREDENTIALS_PATH})

# publishing job
export PACKAGE_UPLOADER_GCS_CREDENTIALS_SECRET=$(retry 5 vault kv get -field value ${PACKAGE_UPLOADER_GCS_CREDENTIALS_PATH})
fi
fi

if [ ${BUILDKITE_PIPELINE_SLUG} == "integrations" ]; then
# FIXME: update condition depending on the pipeline steps triggered
if [[ ${BUILDKITE_STEP_KEY} == "test-integrations" ]]; then
export ELASTIC_PACKAGE_AWS_SECRET_KEY=$(retry 5 vault kv get -field secret_key ${AWS_SERVICE_ACCOUNT_SECRET_PATH})
export ELASTIC_PACKAGE_AWS_ACCESS_KEY=$(retry 5 vault kv get -field access_key ${AWS_SERVICE_ACCOUNT_SECRET_PATH})

export PRIVATE_CI_GCS_CREDENTIALS_SECRET=$(retry 5 vault kv get -field plaintext ${PRIVATE_CI_GCS_CREDENTIALS_PATH})
export JOB_GCS_BUCKET_INTERNAL="fleet-ci-temp-internal"

# Environment variables required by the service deployer
export AWS_SECRET_ACCESS_KEY=${ELASTIC_PACKAGE_AWS_SECRET_KEY}
export AWS_ACCESS_KEY_ID=${ELASTIC_PACKAGE_AWS_ACCESS_KEY}
fi
fi

if [ ${BUILDKITE_PIPELINE_SLUG} == "integrations-serverless" ]; then
if [[ ${BUILDKITE_STEP_KEY} == "test-integrations-serverless-project" ]]; then
export ELASTIC_PACKAGE_AWS_SECRET_KEY=$(retry 5 vault kv get -field secret_key ${AWS_SERVICE_ACCOUNT_SECRET_PATH})
export ELASTIC_PACKAGE_AWS_ACCESS_KEY=$(retry 5 vault kv get -field access_key ${AWS_SERVICE_ACCOUNT_SECRET_PATH})

export PRIVATE_CI_GCS_CREDENTIALS_SECRET=$(retry 5 vault kv get -field plaintext ${PRIVATE_CI_GCS_CREDENTIALS_PATH})
export JOB_GCS_BUCKET_INTERNAL="fleet-ci-temp-internal"

# Environment variables required by the service deployer
export AWS_SECRET_ACCESS_KEY=${ELASTIC_PACKAGE_AWS_SECRET_KEY}
export AWS_ACCESS_KEY_ID=${ELASTIC_PACKAGE_AWS_ACCESS_KEY}

export EC_API_KEY_SECRET=$(retry 5 vault kv get -field apiKey ${EC_TOKEN_PATH})
export EC_HOST_SECRET=$(retry 5 vault kv get -field url ${EC_TOKEN_PATH})
export EC_REGION_SECRET=$(retry 5 vault read -field region_qa ${EC_DATA_PATH})
fi
fi
51 changes: 51 additions & 0 deletions .buildkite/hooks/pre-exit
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
#!/bin/bash

source .buildkite/scripts/common.sh

set -euo pipefail

if [[ "$BUILDKITE_PIPELINE_SLUG" == "integrations" ]]; then
# FIXME: update condition depending on the pipeline steps triggered
if [[ "$BUILDKITE_STEP_KEY" == "test-integrations" ]]; then
unset ELASTIC_PACKAGE_AWS_ACCESS_KEY
unset ELASTIC_PACKAGE_AWS_SECRET_KEY
unset AWS_ACCESS_KEY_ID
unset AWS_SECRET_ACCESS_KEY

# Ensure that kind cluster is deleted
delete_kind_cluster

# Ensure elastic stack is stopped
if [ -f ${ELASTIC_PACKAGE_BIN} ]; then
echo "--- Take down the Elastic stack"
${ELASTIC_PACKAGE_BIN} stack down -v
fi
fi
fi

if [[ "$BUILDKITE_PIPELINE_SLUG" == "integrations-serverless" ]]; then
if [[ "$BUILDKITE_STEP_KEY" == "test-integrations-serverless-project" ]]; then
unset ELASTIC_PACKAGE_AWS_ACCESS_KEY
unset ELASTIC_PACKAGE_AWS_SECRET_KEY
unset AWS_ACCESS_KEY_ID
unset AWS_SECRET_ACCESS_KEY

# Ensure that kind cluster is deleted
delete_kind_cluster

# Ensure elastic stack is stopped
if [ -f ${ELASTIC_PACKAGE_BIN} ]; then
echo "--- Take down the Elastic stack"
export EC_API_KEY=${EC_API_KEY_SECRET}
export EC_HOST=${EC_HOST_SECRET}

${ELASTIC_PACKAGE_BIN} stack down -v

unset EC_API_KEY
unset EC_HOST
fi
fi
fi

unset_secrets
cleanup
36 changes: 36 additions & 0 deletions .buildkite/pipeline.schedule-daily.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# yaml-language-server: $schema=https://raw.githubusercontent.com/buildkite/pipeline-schema/main/schema.json
name: integrations-schedule-daily

env:
SETUP_GVM_VERSION: "v0.5.1"
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"

# The pipeline is triggered by the scheduler every day
steps:
- label: ":white_check_mark: Check go sources"
key: "check"
command: ".buildkite/scripts/check_sources.sh"
agents:
image: "${LINUX_AGENT_IMAGE}"
cpu: "8"
memory: "4G"

- label: "Check integrations in serverless - project: Observability"
key: "trigger-integrations-serverless-obs"
trigger: "integrations-serverless"
build:
env:
SERVERLESS_PROJECT: observability
depends_on:
- step: "check"
allow_failure: false

- label: "Check integrations in serverless - project: Security"
key: "trigger-integrations-serverless-security"
trigger: "integrations-serverless"
build:
env:
SERVERLESS_PROJECT: security
depends_on:
- step: "check"
allow_failure: false
73 changes: 73 additions & 0 deletions .buildkite/pipeline.serverless.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
# yaml-language-server: $schema=https://raw.githubusercontent.com/buildkite/pipeline-schema/main/schema.json

env:
SETUP_GVM_VERSION: "v0.5.1"
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"
DOCKER_COMPOSE_VERSION: "v2.17.2"
KIND_VERSION: 'v0.20.0'
K8S_VERSION: 'v1.27.3'
YQ_VERSION: 'v4.35.2'
# Elastic package settings
# Manage docker output/logs
ELASTIC_PACKAGE_COMPOSE_DISABLE_ANSI: "true"
ELASTIC_PACKAGE_COMPOSE_DISABLE_PULL_PROGRESS_INFORMATION: "true"
# Default license to use by `elastic-package build`
ELASTIC_PACKAGE_REPOSITORY_LICENSE: "licenses/Elastic-2.0.txt"
# Link definitions path (full path to be set in the corresponding step)
ELASTIC_PACKAGE_LINKS_FILE_PATH: "links_table.yml"
# Disable comparison of results in pipeline tests to avoid errors related to GeoIP fields
ELASTIC_PACKAGE_SERVERLESS_PIPELINE_TEST_DISABLE_COMPARE_RESULTS: "true"

steps:
- input: "Input values for the variables"
key: "input-variables"
fields:
- select: "SERVERLESS_PROJECT"
key: "SERVERLESS_PROJECT"
options:
- label: "observability"
value: "observability"
- label: "security"
value: "security"
default: "observability"
if: "build.source == 'ui'"

- wait: ~
if: "build.source == 'ui'"
allow_dependency_failure: false

- label: ":white_check_mark: Check go sources"
key: "check"
command: ".buildkite/scripts/check_sources.sh"
agents:
image: "${LINUX_AGENT_IMAGE}"
cpu: "8"
memory: "4G"

- label: "Check integrations in serverless"
key: "test-integrations-serverless-project"
command: ".buildkite/scripts/test_integrations_with_serverless.sh"
timeout_in_minutes: 120
env:
SERVERLESS: true
FORCE_CHECK_ALL: true
UPLOAD_SAFE_LOGS: 1
agents:
provider: "gcp"
artifact_paths:
- "build/test-results/*.xml"
# - "build/elastic-stack-dump/*/logs/*.log"
# - "build/elastic-stack-dump/*/logs/fleet-server-internal/**/*"
depends_on:
- step: "check"
allow_failure: false

- wait: ~
continue_on_failure: true

- label: ":junit: Junit annotate"
plugins:
- junit-annotate#v2.4.1:
artifacts: "build/test-results/*.xml"
agents:
provider: "gcp" # junit plugin requires docker
54 changes: 52 additions & 2 deletions .buildkite/pipeline.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,55 @@
# yaml-language-server: $schema=https://raw.githubusercontent.com/buildkite/pipeline-schema/main/schema.json

env:
SETUP_GVM_VERSION: "v0.5.1"
LINUX_AGENT_IMAGE: "golang:${GO_VERSION}"
DOCKER_COMPOSE_VERSION: "v2.17.2"
KIND_VERSION: 'v0.20.0'
K8S_VERSION: 'v1.27.3'
YQ_VERSION: 'v4.35.2'
# Elastic package settings
# Manage docker output/logs
ELASTIC_PACKAGE_COMPOSE_DISABLE_ANSI: "true"
ELASTIC_PACKAGE_COMPOSE_DISABLE_PULL_PROGRESS_INFORMATION: "true"
# Default license to use by `elastic-package build`
ELASTIC_PACKAGE_REPOSITORY_LICENSE: "licenses/Elastic-2.0.txt"
# Link definitions path (full path to be set in the corresponding step)
ELASTIC_PACKAGE_LINKS_FILE_PATH: "links_table.yml"
# Disable comparison of results in pipeline tests to avoid errors related to GeoIP fields
ELASTIC_PACKAGE_SERVERLESS_PIPELINE_TEST_DISABLE_COMPARE_RESULTS: "true"

steps:
- label: "Example test"
command: echo "Hello!"
- label: ":white_check_mark: Check go sources"
key: "check"
command: ".buildkite/scripts/check_sources.sh"
agents:
image: "${LINUX_AGENT_IMAGE}"
cpu: "8"
memory: "4G"

# TODO: Pending to migrate stages from https://github.com/elastic/integrations/blob/993537b80456edf2035f2a4826031841116c2019/.ci/Jenkinsfile
# - label: "Publish packages - INCOMPLETE"
# key: "publish-packages"
# command: ".buildkite/scripts/publish_packages.sh" # TODO: missing signature and publishing loops
# agents:
# provider: "gcp"
# depends_on:
# - step: "check"
# allow_failure: false

# - label: "Trigger integrations"
# key: "trigger-integrations"
# command: ".buildkite/scripts/trigger_integrations_in_parallel.sh" # TODO: missing script
# depends_on:
# - step: "publish-packages"
# allow_failure: false

# - wait: ~
# continue_on_failure: true

# - label: ":junit: Junit annotate"
# plugins:
# - junit-annotate#v2.4.1:
# artifacts: "build/test-results/*.xml"
# agents:
# provider: "gcp" # junit plugin requires docker
Loading