Skip to content

[Enhancement] Improve S1 Cloud Funnel Process Events compatibility#11019

Merged
efd6 merged 4 commits intomainfrom
fr-s1-field-compat
Sep 11, 2024
Merged

[Enhancement] Improve S1 Cloud Funnel Process Events compatibility#11019
efd6 merged 4 commits intomainfrom
fr-s1-field-compat

Conversation

@w0rk3r
Copy link
Copy Markdown
Contributor

@w0rk3r w0rk3r commented Sep 5, 2024

Proposed commit message

Improves the S1 Cloud Funnel Process Events parity with other EDR data sources.

Summary

Uses a field alias to map the process integrity field to the one used in the rules based on our Elastic Defend for more straightforward rule conditions. Adds caseless versions of process.name and process.executable as done in #10533.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Author's Checklist

  • [ ]

Related issues

https://github.com/elastic/ia-trade-team/issues/406

@w0rk3r w0rk3r added enhancement New feature or request Integration:sentinel_one_cloud_funnel SentinelOne Cloud Funnel labels Sep 5, 2024
@w0rk3r w0rk3r requested a review from efd6 September 5, 2024 18:54
@w0rk3r w0rk3r self-assigned this Sep 5, 2024
@w0rk3r w0rk3r requested a review from a team as a code owner September 5, 2024 18:54
@andrewkroh andrewkroh added the Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] label Sep 5, 2024
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elasticmachine
Copy link
Copy Markdown

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@w0rk3r w0rk3r requested a review from efd6 September 5, 2024 20:47
Copy link
Copy Markdown
Contributor

@efd6 efd6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please resolve the conflict and then this should be OK.

@w0rk3r w0rk3r requested a review from efd6 September 11, 2024 13:16
Copy link
Copy Markdown
Contributor

@efd6 efd6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for bearing with me on this.

Copy link
Copy Markdown
Contributor

@efd6 efd6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'll handle these since I missed them.

@elasticmachine
Copy link
Copy Markdown

💚 Build Succeeded

History

cc @w0rk3r

@elastic-sonarqube
Copy link
Copy Markdown

@efd6 efd6 merged commit 1527b10 into main Sep 11, 2024
@efd6 efd6 deleted the fr-s1-field-compat branch September 11, 2024 22:51
@elasticmachine
Copy link
Copy Markdown

Package sentinel_one_cloud_funnel - 1.4.0 containing this change is available at https://epr.elastic.co/search?package=sentinel_one_cloud_funnel

harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 4, 2025
… EDR data sources (elastic#11019)

Uses a field alias to map the process integrity field to the one used in the
rules based on our Elastic Defend for more straightforward rule conditions.

Adds caseless versions of process.name and process.executable as done
in elastic#10533.
harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 5, 2025
… EDR data sources (elastic#11019)

Uses a field alias to map the process integrity field to the one used in the
rules based on our Elastic Defend for more straightforward rule conditions.

Adds caseless versions of process.name and process.executable as done
in elastic#10533.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:sentinel_one_cloud_funnel SentinelOne Cloud Funnel Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants