Skip to content

Commit 3d18249

Browse files
authored
Merge branch 'main' into main
2 parents 5e97a20 + a8116ae commit 3d18249

File tree

1,180 files changed

+65169
-12767
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

1,180 files changed

+65169
-12767
lines changed

.buildkite/pipeline.schedule-daily.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ steps:
3434
env:
3535
SERVERLESS: "false"
3636
FORCE_CHECK_ALL: "true"
37-
STACK_VERSION: 8.19.1-SNAPSHOT
37+
STACK_VERSION: 8.19.3-SNAPSHOT
3838
PUBLISH_COVERAGE_REPORTS: "true"
3939
depends_on:
4040
- step: "check"
@@ -48,7 +48,7 @@ steps:
4848
env:
4949
SERVERLESS: "false"
5050
FORCE_CHECK_ALL: "true"
51-
STACK_VERSION: 8.19.1-SNAPSHOT
51+
STACK_VERSION: 8.19.3-SNAPSHOT
5252
STACK_LOGSDB_ENABLED: "true"
5353
PUBLISH_COVERAGE_REPORTS: "false"
5454
depends_on:

.buildkite/pipeline.schedule-weekly.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ steps:
2121
env:
2222
SERVERLESS: "false"
2323
FORCE_CHECK_ALL: "true"
24-
STACK_VERSION: 8.19.1-SNAPSHOT
24+
STACK_VERSION: 8.19.3-SNAPSHOT
2525
PUBLISH_COVERAGE_REPORTS: "false"
2626
ELASTIC_PACKAGE_DISABLE_ELASTIC_AGENT_WOLFI: "true"
2727
depends_on:

.buildkite/scripts/common.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -768,7 +768,7 @@ is_pr_affected() {
768768
# Example:
769769
# https://buildkite.com/elastic/integrations/builds/25606
770770
# https://github.com/elastic/integrations/pull/13810
771-
if git diff --name-only "${commit_merge}" "${to}" | grep -E -v '^(packages/|\.github/(CODEOWNERS|ISSUE_TEMPLATE|PULL_REQUEST_TEMPLATE|workflows/)|README\.md|docs/|catalog-info\.yaml|\.buildkite/(pull-requests\.json|pipeline\.schedule-daily\.yml|pipeline\.schedule-weekly\.yml|pipeline\.backport\.yml))' > /dev/null; then
771+
if git diff --name-only "${commit_merge}" "${to}" | grep -E -v '^(packages/|\.github/(CODEOWNERS|ISSUE_TEMPLATE|PULL_REQUEST_TEMPLATE|workflows/)|CODE_OF_CONDUCT\.md|README\.md|docs/|catalog-info\.yaml|\.buildkite/(pull-requests\.json|pipeline\.schedule-daily\.yml|pipeline\.schedule-weekly\.yml|pipeline\.backport\.yml))' > /dev/null; then
772772
echo "[${package}] PR is affected: found non-package files"
773773
return 0
774774
fi

.github/CODEOWNERS

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -212,6 +212,7 @@
212212
/packages/eset_protect @elastic/security-service-integrations
213213
/packages/ess_billing @elastic/customer-architects
214214
/packages/etcd @elastic/obs-infraobs-integrations
215+
/packages/extrahop @elastic/security-service-integrations
215216
/packages/f5_bigip @elastic/security-service-integrations
216217
/packages/falco @elastic/security-service-integrations
217218
/packages/filestream @elastic/elastic-agent-data-plane
@@ -268,6 +269,7 @@
268269
/packages/httpjson @elastic/security-service-integrations
269270
/packages/ibmmq @elastic/obs-infraobs-integrations
270271
/packages/iis @elastic/obs-infraobs-integrations
272+
/packages/iis_otel @elastic/obs-infraobs-integrations
271273
/packages/imperva @elastic/integration-experience
272274
/packages/imperva_cloud_waf @elastic/security-service-integrations
273275
/packages/influxdb @elastic/obs-infraobs-integrations
@@ -494,6 +496,7 @@
494496
/packages/windows_etw @elastic/sec-windows-platform
495497
/packages/winlog @elastic/sec-windows-platform
496498
/packages/wiz @elastic/security-service-integrations
499+
/packages/wmi @elastic/obs-infraobs-integrations
497500
/packages/zeek @elastic/integration-experience
498501
/packages/zerofox @elastic/security-service-integrations
499502
/packages/zeronetworks @elastic/security-service-integrations

.github/ISSUE_TEMPLATE/integration_bug.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,7 @@ body:
2828
- Amazon Security Lake [amazon_security_lake]
2929
- Anomali [ti_anomali]
3030
- Apache HTTP Server [apache]
31+
- Apache OpenTelemetry Assets [apache_otel]
3132
- Apache Spark [apache_spark]
3233
- Apache Tomcat [apache_tomcat]
3334
- Arbor Peakflow SP Logs (Deprecated) [netscout]
@@ -125,6 +126,7 @@ body:
125126
- Custom Websocket logs [websocket]
126127
- Custom Windows ETW logs [windows_etw]
127128
- Custom Windows Event Logs [winlog]
129+
- Custom WMI Input Package [wmi]
128130
- CyberArk EPM [cyberark_epm]
129131
- CyberArk Privileged Access Security [cyberarkpas]
130132
- Cyberark Privileged Threat Analytics [cyberark_pta]
@@ -139,7 +141,7 @@ body:
139141
- Docker OpenTelemetry Assets [docker_otel]
140142
- Docker [docker]
141143
- Domain Generation Algorithm Detection [dga]
142-
- DomainTools Real Time Unified Feeds [ti_domaintools]
144+
- DomainTools Feeds [ti_domaintools]
143145
- EclecticIQ [ti_eclecticiq]
144146
- Elastic Agent [elastic_agent]
145147
- Elastic APM [apm]
@@ -157,6 +159,7 @@ body:
157159
- ESET PROTECT [eset_protect]
158160
- ESET Threat Intelligence [ti_eset]
159161
- etcd [etcd]
162+
- ExtraHop [extrahop]
160163
- F5 BIG-IP [f5_bigip]
161164
- Falco [falco]
162165
- File Integrity Monitoring [fim]
@@ -191,6 +194,7 @@ body:
191194
- Host Traffic Anomalies [hta]
192195
- HPE Aruba CX [hpe_aruba_cx]
193196
- IBM MQ [ibmmq]
197+
- IIS OpenTelemetry assets [iis_otel]
194198
- IIS [iis]
195199
- Imperva Cloud WAF [imperva_cloud_waf]
196200
- Imperva [imperva]

.github/ISSUE_TEMPLATE/integration_feature_request.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,7 @@ body:
2828
- Amazon Security Lake [amazon_security_lake]
2929
- Anomali [ti_anomali]
3030
- Apache HTTP Server [apache]
31+
- Apache OpenTelemetry Assets [apache_otel]
3132
- Apache Spark [apache_spark]
3233
- Apache Tomcat [apache_tomcat]
3334
- Arbor Peakflow SP Logs (Deprecated) [netscout]
@@ -125,6 +126,7 @@ body:
125126
- Custom Websocket logs [websocket]
126127
- Custom Windows ETW logs [windows_etw]
127128
- Custom Windows Event Logs [winlog]
129+
- Custom WMI Input Package [wmi]
128130
- CyberArk EPM [cyberark_epm]
129131
- CyberArk Privileged Access Security [cyberarkpas]
130132
- Cyberark Privileged Threat Analytics [cyberark_pta]
@@ -139,7 +141,7 @@ body:
139141
- Docker OpenTelemetry Assets [docker_otel]
140142
- Docker [docker]
141143
- Domain Generation Algorithm Detection [dga]
142-
- DomainTools Real Time Unified Feeds [ti_domaintools]
144+
- DomainTools Feeds [ti_domaintools]
143145
- EclecticIQ [ti_eclecticiq]
144146
- Elastic Agent [elastic_agent]
145147
- Elastic APM [apm]
@@ -157,6 +159,7 @@ body:
157159
- ESET PROTECT [eset_protect]
158160
- ESET Threat Intelligence [ti_eset]
159161
- etcd [etcd]
162+
- ExtraHop [extrahop]
160163
- F5 BIG-IP [f5_bigip]
161164
- Falco [falco]
162165
- File Integrity Monitoring [fim]
@@ -191,6 +194,7 @@ body:
191194
- Host Traffic Anomalies [hta]
192195
- HPE Aruba CX [hpe_aruba_cx]
193196
- IBM MQ [ibmmq]
197+
- IIS OpenTelemetry assets [iis_otel]
194198
- IIS [iis]
195199
- Imperva Cloud WAF [imperva_cloud_waf]
196200
- Imperva [imperva]

.github/workflows/bump-elastic-stack-version.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ jobs:
2525
- uses: actions/checkout@v5
2626

2727
- name: Install Updatecli in the runner
28-
uses: updatecli/updatecli-action@419b75cb4d4bd6b50b03da7b33e1e0065d383eaf #v2.89.0
28+
uses: updatecli/updatecli-action@2289ae9c945707079a248f5e4f5743a6592429ef #v2.90.0
2929

3030
- name: Select diff action
3131
if: ${{ github.event_name == 'pull_request' }}

CODE_OF_CONDUCT.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
# Community Code of Conduct
2+
3+
Elastic is dedicated to providing a positive experience for everyone in
4+
Elastic's Open Source Community, regardless of age, caste, citizenship,
5+
disability, education, ethnicity, gender identity or expression, immigration
6+
status, level of experience, neurodiversity, physical appearance or body size,
7+
nationality, socio-economic status, sexual orientation, race, or religion
8+
(or lack thereof). Our products are distributed by design, and with many
9+
languages, perspectives, and cultures, it's easy to lose something in
10+
translation. Respect cultural differences, and don't assume malice. We do not
11+
tolerate harassment or discrimination in any form.
12+
13+
Please see Elastic's [Open Source Community Code of Conduct](https://www.elastic.co/community/codeofconduct)
14+
for the full text of the code.

docs/extend/_publish_an_integration.md

Lines changed: 19 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -3,32 +3,39 @@ mapped_pages:
33
- https://www.elastic.co/guide/en/integrations-developer/current/_publish_an_integration.html
44
---
55

6-
# Publish an integration [_publish_an_integration]
6+
# Publish an integration via Pull Request[_publish_an_integration]
77

8-
When your integration is done, it’s time to open a PR to include it in the integrations repository. Before opening your PR, run:
8+
When your integration is done, it’s time to open a PR to include it in the integrations repository.
9+
Before opening your PR, make sure you have:
910

11+
1. Pass all checks
12+
Run:
1013
```bash
1114
elastic-package check
1215
```
1316

14-
The `check` command ensures the package is built correctly, formatted properly, and aligned with the spec. Passing the `check` command is required before adding your integration to the repository.
17+
This command validates that your package is built correctly, formatted properly, and aligned with the specification. Passing this `check` is required before submitting your integration.
1518

16-
When CI is happy, merge your PR into the integrations repository.
19+
2. Added a new entry into `changelog.yml`
20+
Update the package’s `changelog.yml` with a clear description of your changes for the new version.
1721

18-
CI will kick off a build job for the main branch, which can release your integration to the package-storage. It means that it will open a PR to the Package Storage/snapshot with the built integration if only the package version doesn’t already exist in the storage (hasn’t been released yet).
22+
3. Bumped the package version
23+
If you are releasing new changes, increment the version in your manifest.yml file. This is required for the package to be published.
1924

25+
4. Wrote clear PR title and description
26+
- Use a concise, descriptive title (e.g., `[New Integration] Add Acme Logs integration`).
27+
- In the PR description, summarize what your integration or change does, list key features or fixes, reference related issues, and provide testing instructions.
28+
- Ensure your documentation, sample events, and tests are included and up to date.
2029

21-
## Promote [_promote]
30+
::::{tip}
31+
A well-written PR with clear documentation, versioning, and testing instructions will speed up the review and publishing process!
32+
::::
2233

23-
Now that you’ve tested your integration with {{kib}}, it’s time to promote it to staging or production. Run:
2434

25-
```bash
26-
elastic-package promote
27-
```
35+
When CI is happy, merge your PR into the integrations repository.
2836

29-
The tool will open 2 pull requests (promote and delete) to the package-storage: target and source branches.
37+
Once the PR with the new version of the package is merged, the required CI pipelines are triggered to release that new version into Package Storage V2 and make them available in https://epr.elastic.co.
3038

31-
Please review both pull requests on your own, check if CI is happy and merge - first target, then source. Once any PR is merged, the CI will kick off a job to bake a new Docker image of package-storage (tracking). Ideally the "delete" PR should be merged once the CI job for "promote" is done, as the Docker image of previous stage depends on the later one.
3239

3340
::::{tip}
3441
When you are ready for your changes in the integration to be released, remember to bump up the package version. It is up to you, as the package developer, to decide how many changes you want to release in a single version. For example, you could implement a change in a PR and bump up the package version in the same PR. Or you could implement several changes across multiple pull requests and then bump up the package version in the last of these pull requests or in a separate follow up PR.

docs/extend/add-data-stream.md

Lines changed: 23 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -20,24 +20,39 @@ apache
2020

2121
A data stream defines multiple {{es}} assets, like index templates, ingest pipelines, and field definitions. These assets are loaded into {{es}} when a user installs an integration using the {{fleet}} UI in {{kib}}.
2222

23-
A data stream also defines a policy template. Policy templates include variables that allow users to configure the data stream using the {{fleet}} UI in {{kib}}. Then, the {{agent}} interprets the resulting policy to collect relevant information from the product or service being observed. Policy templates can also define an integration’s supported [`deployment_modes`](/extend/define-deployment-modes.md#deployment_modes).
23+
A data stream also defines a policy template. Policy templates include variables that allow users to configure the data stream using the {{fleet}} UI in {{kib}}. Then, the {{agent}} interprets the resulting policy to collect relevant information from the product or service being observed. Policy templates can also define an integration’s supported [`deployment_modes`](/extend/define-deployment-modes.md#set-deployment-modes).
2424

2525
See [data streams](docs-content://reference/fleet/data-streams.md) for more information.
2626

2727
::::
2828

29+
## How to add a data stream [how-to]
2930

30-
Bootstrap a new data stream using the TUI wizard. In the directory of your package, run:
31+
1. Boostrap a new data stream
32+
33+
In your package directory, run:
3134

3235
```bash
3336
elastic-package create data-stream
3437
```
3538

36-
Follow the prompts to name, title, and select your data stream type. Then, run this command each time you add a new data stream to your integration.
39+
Follow the prompts to set the name, title, and type (logs, metrics, etc.) for the data stream. Repeat this command for each new data stream you want to add.
40+
41+
2. Configure the data stream
42+
43+
After bootstrapping, manually adjust the generated files to suit your use case:
44+
45+
* Define required variables:
46+
In the policy template, specify variables that users can configure (e.g., paths, ports, log levels).
47+
* Define used fields:
48+
Edit the fields/ files to describe the structure and types of data your stream will ingest.
49+
* Define ingest pipeline definitions:
50+
If needed, create or update ingest pipelines to parse, enrich, or transform incoming data before it’s indexed.
51+
* Update the {{agent}} stream configuration:
52+
Ensure the {{agent}}’s stream configuration matches your data collection requirements and references the correct variables and pipelines.
3753

38-
Next, manually adjust the data stream:
54+
3. How data streams are used
3955

40-
* define required variables
41-
* define used fields
42-
* define ingest pipeline definitions (if necessary)
43-
* update the {{agent}}'s stream configuration
56+
* When the integration is installed, each data stream is registered in {{es}} as a managed, time-based resource.
57+
* Data sent to the data stream is automatically routed to the correct backing indices, with lifecycle management (rollover, retention) handled by Elasticsearch.
58+
* Users can query, visualize, and analyze data from each stream in {{kib}}, using the single data stream name (e.g., `logs-apache.access`).

0 commit comments

Comments
 (0)