Skip to content

Conversation

@kcreddy
Copy link
Contributor

@kcreddy kcreddy commented Aug 1, 2025

Proposed commit message

Update the abuse.ch readme to improve the readability and improve the setup experience for users of the integration. Ensure consistency in configuration options and descriptions. Rebrand AbuseCH to abuse.ch. 

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

Screenshots

Screenshot 2025-08-06 at 2 50 00 PM Screenshot 2025-08-06 at 2 49 08 PM Screenshot 2025-08-06 at 2 49 41 PM Screenshot 2025-08-06 at 2 49 20 PM
@kcreddy kcreddy requested a review from a team as a code owner August 1, 2025 16:54
@kcreddy kcreddy self-assigned this Aug 1, 2025
@kcreddy kcreddy added Integration:ti_abusech abuse.ch Category: Integration quality Category: Quality used for SI planning Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Aug 1, 2025
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@kcreddy kcreddy added the documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. label Aug 1, 2025
Comment on lines 114 to 118
### ECS field reference

{{fields "malware"}}

{{fields "malwarebazaar"}}
Copy link
Contributor Author

@kcreddy kcreddy Aug 1, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kgeller, here the generated content could be better.

Screenshot 2025-08-01 at 10 41 37 PM

The collapsable Exported fields sections are listed without knowing which dataset they belong to. It would've been nice if the exported_fields has data stream name just like sample_event.
This wasn't a problem with #14271 as it only contained 1 dataset.

May I know your suggestion here? Do you suggest adding more headers (for each data stream) like we currently have?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point

I'd say we could change it to have the datastream headers, but I'd love to get the opinion of @alaudazzi and @benironside

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Makes sense @kgeller -- adding a header to each data stream would be ideal

Copy link
Contributor Author

@kcreddy kcreddy Aug 6, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@alaudazzi @kgeller I added the headers. Please review and approve the PR if everything looks good.

Comment on lines 31 to 37
## What do I need to use this integration?

### From Elastic

This integration supports both Elastic Agentless-based and Agent-based installations.

#### Agentless-based installation
Copy link
Contributor Author

@kcreddy kcreddy Aug 1, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kgeller, can you confirm which section does installation instructions for Agentless and Agent should go under?
As per the template, all Elastic prerequisites should be under ## What do I need to use this integration, but also the template says the agent instructions should be under ## How do I deploy this integration.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@alaudazzi @benironside could you provide guidance here?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would keep the agent instructions under ## How do I deploy this integration

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@alaudazzi I updated the section. Please review and approve the PR if everything looks good.

@elastic-vault-github-plugin-prod
Copy link

elastic-vault-github-plugin-prod bot commented Aug 1, 2025

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@kcreddy kcreddy requested a review from alaudazzi August 4, 2025 08:22
@kcreddy kcreddy requested a review from efd6 August 4, 2025 16:32
Copy link
Contributor

@kgeller kgeller left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated README lgtm 👍

@andrewkroh andrewkroh added dashboard Relates to a Kibana dashboard bug, enhancement, or modification. enhancement New feature or request labels Aug 7, 2025
Copy link
Contributor

@alaudazzi alaudazzi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed and left some editing suggestions. The structure looks OK.

@elasticmachine
Copy link

💚 Build Succeeded

History

cc @kcreddy

@kcreddy kcreddy merged commit 430377f into elastic:main Aug 11, 2025
9 checks passed
@elastic-vault-github-plugin-prod

Package ti_abusech - 3.3.0 containing this change is available at https://epr.elastic.co/package/ti_abusech/3.3.0/

robester0403 pushed a commit to robester0403/integrations that referenced this pull request Aug 14, 2025
Update the abuse.ch readme to improve the readability and improve the setup experience for users of the integration. Ensure consistency in configuration options and descriptions. Rebrand AbuseCH to abuse.ch.
tehbooom pushed a commit to tehbooom/integrations that referenced this pull request Nov 19, 2025
Update the abuse.ch readme to improve the readability and improve the setup experience for users of the integration. Ensure consistency in configuration options and descriptions. Rebrand AbuseCH to abuse.ch.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Category: Integration quality Category: Quality used for SI planning dashboard Relates to a Kibana dashboard bug, enhancement, or modification. documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:ti_abusech abuse.ch Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

8 participants