[SIEM] Updates process and TLS tables to use ECS 1.5 fields#60854
Merged
tsg merged 5 commits intoelastic:masterfrom Mar 24, 2020
Merged
[SIEM] Updates process and TLS tables to use ECS 1.5 fields#60854tsg merged 5 commits intoelastic:masterfrom
tsg merged 5 commits intoelastic:masterfrom
Conversation
Contributor
|
Pinging @elastic/siem (Team:SIEM) |
angorayc
approved these changes
Mar 23, 2020
Contributor
angorayc
left a comment
There was a problem hiding this comment.
Thanks for updating the query!! Ran and played around on local branch, all looks fine. Good to go when all check passed.
Contributor
Author
|
@elasticmachine merge upstream |
tsg
added a commit
to tsg/kibana
that referenced
this pull request
Mar 24, 2020
…60854) * Added new process filter * Use new ECS TLS fields
gmmorris
added a commit
to gmmorris/kibana
that referenced
this pull request
Mar 24, 2020
* master: (34 commits) [APM] add service map config options to legacy plugin (elastic#61002) [App Arch] migrate legacy CSS to new platform (core_plugins/kibana_react) (elastic#59882) Migrated styles for "share" plugin to new platform (elastic#59981) [ML] Module setup with dynamic model memory estimation (elastic#60656) Drilldowns (elastic#59632) Upgrade mocha dev-dependency from 6.2.2 to 7.1.1 (elastic#60779) [SIEM] Overview: Recent cases widget (elastic#60993) [ML] Functional tests - stabilize df analytics clone tests (elastic#60497) [SIEM] Updates process and TLS tables to use ECS 1.5 fields (elastic#60854) Migrate doc view part of discover (elastic#58094) Revert "[APM] Collect telemetry about data/API performance (elastic#51612)" fix(NA): log rotation watchers usage (elastic#60956) [SIEM] [CASES] Build lego blocks case details view (elastic#60864) Create Painless Lab app (elastic#57538) [SIEM] Move Timeline Template field to first step of rule creation (elastic#60840) [Reporting/New Platform Migration] Use a new config service on server-side (elastic#55882) [Alerting] allow email action to not require auth (elastic#60839) [Maps] Default ES document layer scaling type to clusters and show scaling UI in the create wizard (elastic#60668) [APM] Collect telemetry about data/API performance (elastic#51612) Implement Kibana Login Selector (elastic#53010) ...
tsg
added a commit
that referenced
this pull request
Mar 24, 2020
Contributor
💔 Build Failed
Failed CI Steps
Test FailuresKibana Pipeline / kibana-oss-agent / Chrome UI Functional Tests.test/functional/apps/discover/_errors·js.discover app errors invalid scripted field error is renderedStandard OutStack TraceKibana Pipeline / kibana-intake-agent / Jest Integration Tests.packages/kbn-plugin-generator/integration_tests.running the plugin-generator via 'node scripts/generate_plugin.js plugin-name' with default config then running with es instance 'yarn start' should result in the spec plugin being initialized on kibana's stdoutStandard OutStack TraceKibana Pipeline / kibana-oss-agent / Chrome UI Functional Tests.test/functional/apps/discover/_errors·js.discover app errors invalid scripted field error is renderedStandard OutStack TraceHistory
To update your PR or re-run it, just comment with: |
Contributor
|
Pinging @elastic/security-solution (Team: SecuritySolution) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This adjusts the fields used by the Uncommon Processes and TLS to ECS 1.5.
#60026
#43649
The process changes are easy enough because the code already supported multiple ways to filter the data and this PR just needs to add a new condition (
event.category: process AND event.type: start).For the TLS table, things are more complicated because several of the fields used in the UI are not available in ECS 1.5 and there are no immediate equivalents. More precisely, the common names from Issuer and Subject are no longer separated. Also, Alternative Names are not available.
Upon discussion with @MikePaquette, we've decided to display "Issuer" and "Subject" as columns.
Note that this means that old data won't be shown, but Packetbeat was switched to use ECS 1.4 already in 7.6.
I didn't yet adjust the integration tests, so I expect those to fail for now.
Checklist
Delete any items that are not applicable to this PR.
Documentation was added for features that require explanation or tutorialshis was checked for keyboard-only and screenreader accessibilityThis renders correctly on smaller devices using a responsive layout. (You can test this in your browserThis was checked for cross-browser compatibility, including a check against IE11For maintainers