Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add related.entity field to azure activitylogs default ingest pipeline #11233

Draft
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

orouz
Copy link
Contributor

@orouz orouz commented Sep 24, 2024

Proposed commit message

this PR is part of the cloud security CDR epic. it adds 2 append processors that add the principal_id (event/action origin) and resource_id (event/action target) to a new field - related.entity

the related.entity field is an upcoming ECS field meant to facilitate pivoting around a piece of data.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Related issues

@orouz orouz added enhancement New feature or request Integration:azure Azure Logs labels Sep 24, 2024
@orouz orouz force-pushed the azure_activitylogs_cdr_pipeline branch from 47f2eea to 21b7189 Compare September 24, 2024 12:33
@orouz
Copy link
Contributor Author

orouz commented Sep 25, 2024

/test

@elasticmachine
Copy link

elasticmachine commented Sep 25, 2024

💔 Build Failed

Failed CI Steps

History

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request Integration:azure Azure Logs
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants