Summary
A recent feature in Beats for 8.10 adds file information to each event. Integrations using filestream inputs are failing their system testing against the 8.10 snapshot if the integration doesn't define the fields.
Example
Results of running elastic-package test system -v for trendmicro/deep_security against 8.10-SNAPSHOT:
--- Test results for package: trendmicro - START ---
FAILURE DETAILS:
trendmicro/deep_security filestream:
[0] field "log.file.device_id" is undefined
[1] field "log.file.inode" is undefined
╭────────────┬───────────────┬───────────┬────────────┬────────────────────────────────────────────────────────────────────────────────────────────────────┬───────────────╮
│ PACKAGE │ DATA STREAM │ TEST TYPE │ TEST NAME │ RESULT │ TIME ELAPSED │
├────────────┼───────────────┼───────────┼────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────┼───────────────┤
│ trendmicro │ deep_security │ system │ filestream │ FAIL: one or more errors found in documents stored in logs-trendmicro.deep_security-ep data stream │ 2m12.0360715s │
╰────────────┴───────────────┴───────────┴────────────┴────────────────────────────────────────────────────────────────────────────────────────────────────┴───────────────╯
--- Test results for package: trendmicro - END ---
Done
Error: one or more test cases failed
Depends on elastic/beats#36695
Impacted integrations
Appears to impact several integration with system tests using type: filestream (list may be incomplete).
obs-infraobs-integrations: #7716
security-external-integrations: #8014
obs-cloud-monitoring : #8068
Summary
A recent feature in Beats for 8.10 adds file information to each event. Integrations using
filestreaminputs are failing their system testing against the 8.10 snapshot if the integration doesn't define the fields.Example
Results of running
elastic-package test system -vfortrendmicro/deep_securityagainst8.10-SNAPSHOT:Depends on elastic/beats#36695
Impacted integrations
Appears to impact several integration with system tests using
type: filestream(list may be incomplete).obs-infraobs-integrations: #7716
security-external-integrations: #8014
[ ] juniper_junos (deprecated)[ ] juniper_netscreen (deprecated)obs-cloud-monitoring : #8068