Skip to content

Conversation

@taylor-swanson
Copy link
Contributor

@taylor-swanson taylor-swanson commented Oct 29, 2025

Proposed commit message

  • Add append processor to pipeline on_failure handlers to preserve event.original.
  • Add append processor to pipeline to preserve event.original if error.message is set.

Integrations

  • sophos
  • squid
  • stormshield
  • suricata
  • syslog_router
  • tetragon
  • watchguard_firebox
  • zeek

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
    - [ ] I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

@taylor-swanson taylor-swanson self-assigned this Oct 29, 2025
@taylor-swanson taylor-swanson added enhancement New feature or request Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience] labels Oct 29, 2025
- Added append processor to global on_failure to preserve event original
- Added append processor to default pipelines to preserve event original if error.message is set

Affects the following integrations:

- sophos
- squid
- stormshield
- suricata
- syslog_router
- tetragon
- watchguard_firebox
- zeek
@elasticmachine
Copy link

💚 Build Succeeded

cc @taylor-swanson

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:sophos Sophos Integration:squid Squid Proxy Integration:stormshield StormShield SNS Integration:suricata Suricata Integration:syslog_router Syslog Router Integration:tetragon Cilium Tetragon Integration:watchguard_firebox WatchGuard Firebox Integration:zeek Zeek Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants