SEI package style now requires that the global on_failure sets error.kind to "pipeline_error". New package generally have this behaviour, but existing packages need to be brought up to date.
Current packages (identified by CODEOWNERS) that do not do this are (package, data stream name and file):
1password 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
akamai 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
atlassian_bitbucket 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
atlassian_confluence 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
atlassian_jira 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
auditd 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
auditd_manager 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
auth0 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
azure_frontdoor 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
barracuda_cloudgen_firewall 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
bitdefender 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
bluecoat 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
box_events 1password,[ab]*: ensure event.kind is correctly set for pipeline errors #6599
carbon_black_cloud c*: ensure event.kind is correctly set for pipeline errors #6613
carbonblack_edr c*: ensure event.kind is correctly set for pipeline errors #6613
cef c*: ensure event.kind is correctly set for pipeline errors #6613
cisco_aironet cisco*: ensure event.kind is correctly set for pipeline errors #6600
cisco_asa cisco*: ensure event.kind is correctly set for pipeline errors #6600
cisco_secure_email_gateway cisco*: ensure event.kind is correctly set for pipeline errors #6600
cisco_duo cisco*: ensure event.kind is correctly set for pipeline errors #6600
cisco_ftd cisco*: ensure event.kind is correctly set for pipeline errors #6600
cisco_ise cisco*: ensure event.kind is correctly set for pipeline errors #6600
cisco_meraki cisco*: ensure event.kind is correctly set for pipeline errors #6600
cisco_nexus cisco*: ensure event.kind is correctly set for pipeline errors #6600
cisco_secure_endpoint cisco*: ensure event.kind is correctly set for pipeline errors #6600
cisco_umbrella cisco*: ensure event.kind is correctly set for pipeline errors #6600
citrix_waf c*: ensure event.kind is correctly set for pipeline errors #6613
cloudflare c*: ensure event.kind is correctly set for pipeline errors #6613
crowdstrike c*: ensure event.kind is correctly set for pipeline errors #6613
cylance c*: ensure event.kind is correctly set for pipeline errors #6613
darktrace [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
f5 [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
f5_bigip [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
fim [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
fireeye [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
forcepoint_web [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
fortinet_forticlient [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
fortinet_fortiedr [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
fortinet_fortigate [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
fortinet_fortimail [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
gcp [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
github [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
google_workspace [dfg]*: ensure event.kind is correctly set for pipeline errors #6614
hashicorp_vault [hi]*: ensure event.kind is correctly set for pipeline errors #6616
hid_bravura_monitor [hi]*: ensure event.kind is correctly set for pipeline errors #6616
imperva [hi]*: ensure event.kind is correctly set for pipeline errors #6616
infoblox_bloxone_ddi [hi]*: ensure event.kind is correctly set for pipeline errors #6616
infoblox_nios [hi]*: ensure event.kind is correctly set for pipeline errors #6616
iptables iptables: ensure event.kind is correctly set for pipeline errors #6642 (attempted in [hi]*: ensure event.kind is correctly set for pipeline errors #6616 — see note in revert)
jamf_compliance_reporter jamf_compliance_reporter: ensure event.kind is correctly set for pipeline errors #6615
jumpcloud [jkl]*: ensure event.kind is correctly set for pipeline errors #6617
juniper_junos [jkl]*: ensure event.kind is correctly set for pipeline errors #6617
juniper_netscreen [jkl]*: ensure event.kind is correctly set for pipeline errors #6617
keycloak [jkl]*: ensure event.kind is correctly set for pipeline errors #6617
lastpass [jkl]*: ensure event.kind is correctly set for pipeline errors #6617
lyve_cloud [jkl]*: ensure event.kind is correctly set for pipeline errors #6617
m365_defender m*: ensure event.kind is correctly set for pipeline errors #6661
mattermost m*: ensure event.kind is correctly set for pipeline errors #6661
microsoft_defender_endpoint m*: ensure event.kind is correctly set for pipeline errors #6661
microsoft_dhcp m*: ensure event.kind is correctly set for pipeline errors #6661
microsoft_exchange_online_message_trace m*: ensure event.kind is correctly set for pipeline errors #6661
mimecast [mimecast] Ensure event.kind is correctly set for pipeline errors #6627
modsecurity [modsecurity] Ensure event.kind is correctly set for pipeline errors #6672
mysql_enterprise m*: ensure event.kind is correctly set for pipeline errors #6661
netflow [netflow] Ensure event.kind is correctly set for pipeline errors #6628
netscout [np]*: ensure event.kind is correctly set for pipeline errors #6662
netskope [np]*: ensure event.kind is correctly set for pipeline errors #6662
network_traffic [network_traffic] Ensure event.kind is correctly set for pipeline errors #6641
o365 [o365] Ensure event.kind is correctly set for pipeline errors #6626
osquery [osquery] Ensure event.kind is correctly set for pipeline errors #6640
panw_cortex_xdr [np]*: ensure event.kind is correctly set for pipeline errors #6662
panw [np]*: ensure event.kind is correctly set for pipeline errors #6662
pfsense [np]*: ensure event.kind is correctly set for pipeline errors #6662
ping_one [np]*: ensure event.kind is correctly set for pipeline errors #6662
proofpoint_tap [np]*: ensure event.kind is correctly set for pipeline errors #6662
pulse_connect_secure [np]*: ensure event.kind is correctly set for pipeline errors #6662
qnap_nas [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
radware [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
santa [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
sentinel_one [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
slack [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
snort [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
snyk [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
sonicwall_firewall [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
sophos [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
sophos_central [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
squid [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
suricata [Suricata] Ensure event.kind is correctly set for pipeline errors #6625
symantec_endpoint [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
sysmon_linux [qrs]*: ensure event.kind is correctly set for pipeline errors #6663
system_audit [system_audit] Ensure event.kind is correctly set for pipeline errors #6639
tanium [tanium] Ensure event.kind is correctly set for pipeline errors #6660
tenable_sc [tenable_sc] Ensure event.kind is correctly set for pipeline errors #6659
thycotic_ss [thycotic_ss] Ensure event.kind is correctly set for pipeline errors #6658
ti_abusech [ti_abusech] Ensure event.kind is correctly set for pipeline errors #6629
ti_anomali [ti_anomali] Ensure event.kind is correctly set for pipeline errors #6630
ti_cif3 [ti_cif3] Ensure event.kind is correctly set for pipeline errors #6631
ti_cybersixgill [ti_cybersixgill] Ensure event.kind is correctly set for pipeline errors #6632
ti_misp [ti_misp] Ensure event.kind is correctly set for pipeline errors #6633
ti_otx [ti_otx] Ensure event.kind is correctly set for pipeline errors #6634
ti_rapid7_threat_command [ti_rapid7_threat_command] Ensure event.kind is correctly set for pipeline errors #6635
ti_recordedfuture [ti_recordedfuture] Ensure event.kind is correctly set for pipeline errors #6636
ti_threatq [ti_threatq] Ensure event.kind is correctly set for pipeline errors #6637
tines [tines] Ensure event.kind is correctly set for pipeline errors #6655
trendmicro [trendmicro] Ensure event.kind is correctly set for pipeline errors #6656
trend_micro_vision_one [trend_micro_vision_one] Ensure event.kind is correctly set for pipeline errors #6657
windows [Windows] Ensure event.kind is correctly set for pipeline errors #6612
zeek [zeek] Ensure event.kind is correctly set for pipeline errors #6638
zerofox [zerofox] Ensure event.kind is correctly set for pipeline errors #6654
zoom [zoom] Ensure event.kind is correctly set for pipeline errors #6653
zscaler_zia [zscaler_zia] Ensure event.kind is correctly set for pipeline errors #6652
zscaler_zpa [zscaler_zpa] Ensure event.kind is correctly set for pipeline errors #6651
zeronetworks [zeronetworks] Ensure event.kind is correctly set for pipeline errors #6650
SEI package style now requires that the global
on_failuresetserror.kindto "pipeline_error". New package generally have this behaviour, but existing packages need to be brought up to date.Current packages (identified by CODEOWNERS) that do not do this are (package, data stream name and file):