-
Notifications
You must be signed in to change notification settings - Fork 522
m365_defender: fix assignment of windows os identity and posix hosts #10953
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
a5bd988 to
7d76f05
Compare
🚀 Benchmarks reportTo see the full report comment with |
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
chemamartinez
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
7d76f05 to
71473c5
Compare
|
Waiting for a bit to see about getting a WSL test case to include in testing. |
71473c5 to
2de1bd9
Compare
|
Note additional change here that affects POSIX hosts. See rationale in PR description. If this is too far, I'm happy to back out the second commit which makes this change. |
💚 Build Succeeded
History
cc @efd6 |
|
|
Package m365_defender - 2.15.0 containing this change is available at https://epr.elastic.co/search?package=m365_defender |
…lastic#10953) Ensure that windows hosts are not labelled as macos or linux by examining POSIX details fields. Also label otherwise unknown host types as unix if they do have a POSIX details on the basis that Windows hosts have already been excluded and so all remaining POSIX host types are Unix.
…lastic#10953) Ensure that windows hosts are not labelled as macos or linux by examining POSIX details fields. Also label otherwise unknown host types as unix if they do have a POSIX details on the basis that Windows hosts have already been excluded and so all remaining POSIX host types are Unix.


Proposed commit message
Ensure that windows hosts are not labelled as macos or linux by examining
POSIX details fields. Also label otherwise unknown host types as unix if they
do have a POSIX details on the basis that Windows hosts have already been
excluded and so all remaining POSIX host types are Unix.
Checklist
changelog.ymlfile.Author's Checklist
How to test this PR locally
Related issues
host.os.typeto windows for MacOS devices #10680Screenshots