-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[SIEM] Uses autonomous_system as new ECS field #43925
Conversation
Pinging @elastic/siem |
💚 Build Succeeded |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
checked out, ran the tests and then tested this with source and destination.
This PR does what it advertises and cleans things up more so 👍
Thanks @FrankHassanabad for the review. Opened up a new issue for the IP Overview details not updating when |
retest |
jenkins retest |
retest |
💔 Build Failed |
retest |
1 similar comment
retest |
Retest |
💔 Build Failed |
retest |
💔 Build Failed |
💚 Build Succeeded |
💔 Build Failed |
Summary
ECS has added an
as.*
field set (elastic/ecs#341, docs) and @andrewkroh has updated a bunch of Filebeat pipelines to use those fields (elastic/beats#13036).This PR changes our references to
autonomous_system.*
change toas.*
in the SIEM app. I don't see any data coming through forautonomous_system.*
in the first place. After this change, we are getting that data now when it is there on Ip Overview#43746
Checklist
Use
strikethroughsto remove checklist items you don't feel are applicable to this PR.This was checked for cross-browser compatibility, including a check against IE11Any text added follows EUI's writing guidelines, uses sentence case text and includes i18n supportDocumentation was added for features that require explanation or tutorialsThis was checked for keyboard-only and screenreader accessibilityFor maintainers
This was checked for breaking API changes and was labeled appropriatelyThis includes a feature addition or change that requires a release note and was labeled appropriately