-
Notifications
You must be signed in to change notification settings - Fork 522
Fix network.transport and network.protocol issues in m365_defender #10418
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
…rt according to ECS. Added test logs to cover missing protocols and updated expected logs.
efd6
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please add a changelog entry and bump the patch version in manifest.yml.
|
Whoops forgot to do those. Should be updated @efd6! |
|
/test |
🚀 Benchmarks reportTo see the full report comment with |
efd6
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nit then LGTM
Co-authored-by: Dan Kortschak <[email protected]>
|
Hey @efd6, is this good to go? |
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
|
/test |
|
💚 Build Succeeded
History
|
efd6
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks
|
Package m365_defender - 2.14.2 containing this change is available at https://epr.elastic.co/search?package=m365_defender |




Proposed commit message
The
network.transportandnetwork.protocolfields are not being set properly. Often the transport value (udp/tcp) is getting set to the protocol field and the protocol is never set at all. The changes I made to thetest-device.log-expected.jsonfile should demonstrate these issues.I also added handling for missing protocols and added example logs for the ones I had the ability to produce.
As a side note, I am happy to convert the entire logic for handling transport/protocol to a single script processor but I figured using the built in processors is easier for maintainability.
Checklist
changelog.ymlfile.Author's Checklist
How to test this PR locally
Related issues
Screenshots