Skip to content

Commit 5631bff

Browse files
authored
sentinel_one_cloud_funnel: fix original data preservation for gcs (#9627)
1 parent 0284a6e commit 5631bff

File tree

4 files changed

+14
-3
lines changed

4 files changed

+14
-3
lines changed

packages/sentinel_one_cloud_funnel/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "0.14.1"
3+
changes:
4+
- description: Add missing event preservation template expansions for GCS input.
5+
type: bugfix
6+
link: https://github.com/elastic/integrations/pull/9627
27
- version: "0.14.0"
38
changes:
49
- description: Improve `event.type` and `event.action` mappings, fix missing `preserve_original_event` setting for GCS input.

packages/sentinel_one_cloud_funnel/data_stream/event/agent/stream/gcs.yml.hbs

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,12 @@ timestamp_epoch: {{timestamp_epoch}}
3232
{{/if}}
3333
{{#if tags}}
3434
tags:
35+
{{#if preserve_original_event}}
36+
- preserve_original_event
37+
{{/if}}
38+
{{#if preserve_duplicate_custom_fields}}
39+
- preserve_duplicate_custom_fields
40+
{{/if}}
3541
{{#each tags as |tag|}}
3642
- {{tag}}
3743
{{/each}}

packages/sentinel_one_cloud_funnel/data_stream/event/elasticsearch/ingest_pipeline/pipeline-registry.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ processors:
1919
- set:
2020
field: event.action
2121
value: [creation]
22-
if: ctx.sentinel_one_cloud_funnel?.event?.type != null &&
22+
if: ctx.sentinel_one_cloud_funnel?.event?.type != null &&
2323
(
2424
ctx.sentinel_one_cloud_funnel?.event?.meta_event_name.toLowerCase().contains('regvaluecreate') ||
2525
ctx.sentinel_one_cloud_funnel?.event?.meta_event_name.toLowerCase().contains('regkeycreate')
@@ -31,7 +31,7 @@ processors:
3131
- set:
3232
field: event.action
3333
value: [deletion]
34-
if: ctx.sentinel_one_cloud_funnel?.event?.type != null &&
34+
if: ctx.sentinel_one_cloud_funnel?.event?.type != null &&
3535
(
3636
ctx.sentinel_one_cloud_funnel?.event?.meta_event_name.toLowerCase().contains('regvaluedelete') ||
3737
ctx.sentinel_one_cloud_funnel?.event?.meta_event_name.toLowerCase().contains('regkeydelete')

packages/sentinel_one_cloud_funnel/manifest.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
format_version: "3.0.2"
22
name: sentinel_one_cloud_funnel
33
title: SentinelOne Cloud Funnel
4-
version: "0.14.0"
4+
version: "0.14.1"
55
description: Collect logs from SentinelOne Cloud Funnel with Elastic Agent.
66
type: integration
77
categories: ["security", "edr_xdr"]

0 commit comments

Comments
 (0)