-
Notifications
You must be signed in to change notification settings - Fork 515
[proofpoint_essentials] Initial Release of Proofpoint Essentials #16073
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
[proofpoint_essentials] Initial Release of Proofpoint Essentials #16073
Conversation
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
🚀 Benchmarks reportTo see the full report comment with |
💚 Build Succeeded
|
| description: The rewrite status of the message. | ||
| - name: customer_eid | ||
| type: keyword | ||
| description: The customers entity ID. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| description: The customers entity ID. | |
| description: The customer's entity ID. |
(throughout)
| fields: | ||
| - name: content_type | ||
| type: keyword | ||
| description: The true, detected Content-Type of the messagePart. This may differ from the oContentType value. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| description: The true, detected Content-Type of the messagePart. This may differ from the oContentType value. | |
| description: The true, detected Content-Type of the messagePart. This may differ from the `o_content_type` value. |
(throughout)
I think probably that generally the camelCase names in the descriptions should be converted to snake_case to avoid confusion since all the fields have been converted to snake_case.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Currently the filters are acting at the dashboard level. Can they be moved to the visualisation level so that users are not able to accidentally remove them?
| if (ctx.proofpoint_essentials.threat.threats_info_map instanceof List) { | ||
| for (item in ctx.proofpoint_essentials.threat.threats_info_map) { | ||
| if (item?.threat_time instanceof String && Instant.parse(item.threat_time).isAfter(ts)) { | ||
| ctx['@timestamp'] = item.threat_time; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| ctx['@timestamp'] = item.threat_time; | |
| ts = item.threat_time; |
| } | ||
| if (ctx.proofpoint_essentials?.threat?.event_type == 'clicks_blocked' || ctx.proofpoint_essentials?.threat?.event_type == 'clicks_permitted') { | ||
| if (ctx.proofpoint_essentials.threat.threat_time instanceof String && Instant.parse(ctx.proofpoint_essentials.threat.threat_time).isAfter(ts)) { | ||
| ctx['@timestamp'] = ctx.proofpoint_essentials.threat.threat_time; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| ctx['@timestamp'] = ctx.proofpoint_essentials.threat.threat_time; | |
| ts = ctx.proofpoint_essentials.threat.threat_time; |
| if (ctx.proofpoint_essentials.threat.threat_time instanceof String && Instant.parse(ctx.proofpoint_essentials.threat.threat_time).isAfter(ts)) { | ||
| ctx['@timestamp'] = ctx.proofpoint_essentials.threat.threat_time; | ||
| } | ||
| } |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| } | |
| } | |
| ctx['@timestamp'] = ts; |
Proposed commit message
Note
elastic-packageissue is tracked at Allow data stream overrides in system tests for specific integration packages elastic-package#1917Checklist
changelog.ymlfile.How to test this PR locally
Related issues
Screenshots