Skip to content

Remove ecs mappings from integration transform definition #224221

@maxcold

Description

@maxcold

Motivation

After

is done and released we should be able to remove explicit ECS mappings from integration transform definitions, eg. https://github.com/elastic/integrations/blob/main/packages/wiz/elasticsearch/transform/latest_cdr_misconfigurations/fields/ecs.yml as they should be covered by ecs@mappings component template added to the destination index template

The list of such integrations is growing, the best source at the time of writing is the list of kibana_system priviliges https://github.com/maxcold/elasticsearch/blob/main/x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/security/authz/store/KibanaOwnedReservedRoleDescriptors.java#L469

Definition of done

  • Explicit ECS mappings are removed from CDR related integrations

Out of scope

Related tasks/epics

Team tag

@elastic/kibana-cloud-security-posture

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions