Skip to content

cisco_ftd: remove invalid values from ECS fields#3344

Merged
efd6 merged 2 commits intoelastic:mainfrom
efd6:3328-cisco-ftd
May 15, 2022
Merged

cisco_ftd: remove invalid values from ECS fields#3344
efd6 merged 2 commits intoelastic:mainfrom
efd6:3328-cisco-ftd

Conversation

@efd6
Copy link
Contributor

@efd6 efd6 commented May 12, 2022

What does this PR do?

This removes invalid values from the event.outcome field.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Screenshots

@efd6 efd6 added bug Something isn't working, use only for issues Team:Security-External Integrations Integration:cisco_ftd Cisco FTD labels May 12, 2022
@efd6 efd6 self-assigned this May 12, 2022
@efd6 efd6 requested a review from a team as a code owner May 12, 2022 03:48
@elasticmachine
Copy link

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@elasticmachine
Copy link

elasticmachine commented May 12, 2022

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2022-05-12T07:54:45.045+0000

  • Duration: 18 min 56 sec

Test stats 🧪

Test Results
Failed 0
Passed 18
Skipped 0
Total 18

🤖 GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@elasticmachine
Copy link

elasticmachine commented May 12, 2022

🌐 Coverage report

Name Metrics % (covered/total) Diff
Packages 100.0% (1/1) 💚
Files 100.0% (1/1) 💚 3.597
Classes 100.0% (1/1) 💚 3.597
Methods 100.0% (17/17) 💚 11.753
Lines 66.522% (1073/1613) 👎 -22.591
Conditionals 100.0% (0/0) 💚

Copy link
Contributor

@adriansr adriansr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I understand this same change will be needed for the cisco_asa integration (same pipeline) and also to the cisco module in Beats

@efd6
Copy link
Contributor Author

efd6 commented May 12, 2022

Yes, I've just confirmed that the cisco_asa input will see the same data that causes this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working, use only for issues Integration:cisco_ftd Cisco FTD

Projects

None yet

Development

Successfully merging this pull request may close these issues.

cisco_ftd, cisco_duo using invalid values according to ECS

3 participants