-
Notifications
You must be signed in to change notification settings - Fork 562
[meta] Upgrade integrations to ECS 8.17 #11952
Copy link
Copy link
Open
Labels
Team:Asset MgtSecurity Assets Management team [elastic/security-asset-management]Security Assets Management team [elastic/security-asset-management]Team:Cloud SecurityCloud Security team [elastic/cloud-security-posture]Cloud Security team [elastic/cloud-security-posture]Team:Cloudnative-MonitoringCloud Native Monitoring team [elastic/obs-cloudnative-monitoring]Cloud Native Monitoring team [elastic/obs-cloudnative-monitoring]Team:EcosystemPackages Ecosystem team [elastic/ecosystem]Packages Ecosystem team [elastic/ecosystem]Team:Elastic-AgentPlatform - Ingest - Agent [elastic/elastic-agent]Platform - Ingest - Agent [elastic/elastic-agent]Team:Elastic-Agent-Data-PlaneAgent Data Plane team [elastic/elastic-agent-data-plane]Agent Data Plane team [elastic/elastic-agent-data-plane]Team:FleetFleet team [elastic/fleet]Fleet team [elastic/fleet]Team:Security-Deployment and DevicesDEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]Team:Security-Linux PlatformLinux Platform Security team [elastic/sec-linux-platform]Linux Platform Security team [elastic/sec-linux-platform]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Security-Windows PlatformSecurity Windows Platform team [elastic/sec-windows-platform]Security Windows Platform team [elastic/sec-windows-platform]Team:Stack MonitoringStack Monitoring team [elastic/stack-monitoring]Stack Monitoring team [elastic/stack-monitoring]Team:obs-ds-hosted-servicesObservability Hosted Services team [elastic/obs-ds-hosted-services]Observability Hosted Services team [elastic/obs-ds-hosted-services]meta
Metadata
Metadata
Assignees
Labels
Team:Asset MgtSecurity Assets Management team [elastic/security-asset-management]Security Assets Management team [elastic/security-asset-management]Team:Cloud SecurityCloud Security team [elastic/cloud-security-posture]Cloud Security team [elastic/cloud-security-posture]Team:Cloudnative-MonitoringCloud Native Monitoring team [elastic/obs-cloudnative-monitoring]Cloud Native Monitoring team [elastic/obs-cloudnative-monitoring]Team:EcosystemPackages Ecosystem team [elastic/ecosystem]Packages Ecosystem team [elastic/ecosystem]Team:Elastic-AgentPlatform - Ingest - Agent [elastic/elastic-agent]Platform - Ingest - Agent [elastic/elastic-agent]Team:Elastic-Agent-Data-PlaneAgent Data Plane team [elastic/elastic-agent-data-plane]Agent Data Plane team [elastic/elastic-agent-data-plane]Team:FleetFleet team [elastic/fleet]Fleet team [elastic/fleet]Team:Security-Deployment and DevicesDEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]Team:Security-Linux PlatformLinux Platform Security team [elastic/sec-linux-platform]Linux Platform Security team [elastic/sec-linux-platform]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Security-Windows PlatformSecurity Windows Platform team [elastic/sec-windows-platform]Security Windows Platform team [elastic/sec-windows-platform]Team:Stack MonitoringStack Monitoring team [elastic/stack-monitoring]Stack Monitoring team [elastic/stack-monitoring]Team:obs-ds-hosted-servicesObservability Hosted Services team [elastic/obs-ds-hosted-services]Observability Hosted Services team [elastic/obs-ds-hosted-services]meta
Type
Fields
Give feedbackNo fields configured for issues without a type.
Guide
It is recommended to split the changes into smaller PRs to limit the number of changed files. Generally speaking, 10 integrations per PR is a good number to target.
Automated method
Use the
ecs-updatetool which can be found here.Once PR is filed, the changelogs will need to be updated with the correct PR number.
Manual method
Update ECS references in integrations to version 8.17.
_dev/build/build.ymltov8.17.0ECS 8.17 Changes
https://github.com/elastic/ecs/releases/tag/v8.17.0
Schema Changes
Bugfixes
Improvements
Integrations
@elastic/cloud-security-posture:
@elastic/ecosystem:
@elastic/elastic-agent:
@elastic/elastic-agent-data-plane:
@elastic/fleet:
@elastic/obs-cloudnative-monitoring:
@elastic/obs-ds-hosted-services:
@elastic/obs-ds-intake-services:
@elastic/obs-infraobs-integrations:
@elastic/sec-deployment-and-devices:
Update Deployment and Devices integrations to ECS 8.17.0 (part 1) #12569
Update Deployment and Devices integrations to ECS 8.17.0 (part 2) #12571
Update Deployment and Devices integrations to ECS 8.17.0 (part 3) #12572
Update Deployment and Devices integrations to ECS 8.17.0 (part 4) #12574
@elastic/sec-linux-platform:
@elastic/sec-windows-platform: #12636
@elastic/security-asset-management:
@elastic/security-service-integrations:
Update Security Service integrations to ECS 8.17.0 (part 1) #14158
1password
abnormal_security
akamai
amazon_security_lake
atlassian_bitbucket
atlassian_confluence
atlassian_jira
auth0
authentik
aws_bedrock
azure_blob_storage
azure_frontdoor
azure_network_watcher_nsg
azure_network_watcher_vnet
barracuda
barracuda_cloudgen_firewall
bbot
bitdefender
bitwarden
blacklens
box_events
canva
carbon_black_cloud
carbonblack_edr
cel
checkpoint_harmony_endpoint
cisa_kevs
cisco_duo
cisco_meraki
cisco_secure_endpoint
cisco_umbrella
cloudflare
cloudflare_logpush
corelight
cribl
crowdstrike
cyberark_pta
cyberarkpas
cybereason
cylance
darktrace
digital_guardian
entityanalytics_entra_id
entityanalytics_okta
eset_protect
f5
f5_bigip
falco
fireeye
first_epss
forcepoint_web
forgerock
gcp_pubsub
gigamon
github
gitlab
google_cloud_storage
google_scc
google_workspace
http_endpoint
httpjson
imperva_cloud_waf
infoblox_bloxone_ddi
infoblox_nios
jamf_compliance_reporter
jamf_pro
jamf_protect
jumpcloud
keycloak
lastpass
lumos
lyve_cloud
m365_defender
mattermost
menlo
microsoft_defender_cloud
microsoft_defender_endpoint
microsoft_exchange_online_message_trace
microsoft_sentinel
mimecast
netskope
o365
okta
opencanary
panw_cortex_xdr
ping_one
pps
prisma_access
prisma_cloud
proofpoint_on_demand
proofpoint_tap
pulse_connect_secure
qualys_vmdr
rapid7_insightvm
santa
sentinel_one
sentinel_one_cloud_funnel
servicenow
slack
snyk
sophos_central
spycloud
sublime_security
symantec_edr_cloud
symantec_endpoint
symantec_endpoint_security
tanium
teleport
tenable_io
tenable_sc
threat_map
thycotic_ss
ti_abusech
ti_anomali
ti_cif3
ti_crowdstrike
ti_custom
ti_cybersixgill
ti_eclecticiq
ti_eset
ti_maltiverse
ti_mandiant_advantage
ti_misp
ti_opencti
ti_otx
ti_rapid7_threat_command
ti_recordedfuture
ti_threatconnect
ti_threatq
ti_util
tines
trellix_edr_cloud
trellix_epo_cloud
trend_micro_vision_one
trendmicro
vectra_detect
websocket
wiz
zerofox
zeronetworks
zoom
zscaler_zia
zscaler_zpa
@elastic/stack-monitoring: