[windows.powershell_operational] Handle ContextInfo containing multi-line values#16013
[windows.powershell_operational] Handle ContextInfo containing multi-line values#16013
Conversation
|
Added two sample events one with back to back new lines and one without as the original record I was trying to fix had two which caused further issues |
🚀 Benchmarks reportTo see the full report comment with |
|
Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform) |
|
Pinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane) |
leehinman
left a comment
There was a problem hiding this comment.
changelog/manifest conflict needs to be fixed. but pipeline changes LGTM
|
Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as |
…arded pipeline - Revert accidental reorder of message/log in applocker test expected output - Apply field_split fix to forwarded powershell_operational pipeline for consistency
36a7de0 to
50a5257
Compare
💚 Build Succeeded
History
|
|
Package windows - 3.6.1 containing this change is available at https://epr.elastic.co/package/windows/3.6.1/ |
…line values (elastic#16013) * Account for spaces within ContextInfo values * Add changelog and bump version * fix: revert unrelated AppLocker change, apply ContextInfo fix to forwarded pipeline - Revert accidental reorder of message/log in applocker test expected output - Apply field_split fix to forwarded powershell_operational pipeline for consistency --------- Co-authored-by: Marc Guasch <marc.guasch@elastic.co>
Proposed commit message
See title
Checklist
changelog.ymlfile.Related issues