Skip to content

Conversation

@taylor-swanson
Copy link
Contributor

@taylor-swanson taylor-swanson commented Oct 29, 2025

Proposed commit message

  • Add append processor to pipeline on_failure handlers to preserve event.original.
  • Add append processor to pipeline to preserve event.original if error.message is set.

Integrations

  • citrix_waf
  • endace
  • fortinet_fortiedr
  • fortinet_fortigate
  • fortinet_fortimail
  • fortinet_fortimanager
  • fortinet_fortiproxy
  • goflow2
  • hashicorp_vault
  • hpe_aruba_cx

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
    - [ ] I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

@taylor-swanson taylor-swanson self-assigned this Oct 29, 2025
@taylor-swanson taylor-swanson added enhancement New feature or request Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience] labels Oct 29, 2025
@taylor-swanson taylor-swanson force-pushed the chore/event-original-part2 branch from e528932 to 6b6fb30 Compare October 29, 2025 17:28
@taylor-swanson taylor-swanson added Integration:hashicorp_vault Hashicorp Vault Integration:citrix_waf Citrix Web App Firewall Integration:fortinet_fortigate Fortinet FortiGate Firewall Logs Integration:fortinet_fortiproxy Fortinet FortiProxy Integration:fortinet_fortiedr Fortinet FortiEDR Logs Integration:fortinet_fortimail Fortinet FortiMail Integration:fortinet_fortimanager Fortinet FortiManager Logs Integration:goflow2 GoFlow2 logs (Community supported) Integration:hpe_aruba_cx HPE Aruba CX Integration:endace Endace (Partner supported) labels Oct 29, 2025
- Added append processor to global on_failure to preserve event original - Added append processor to default pipelines to preserve event original if error.message is set Affects the following integrations: - citrix_waf - endace - fortinet_fortiedr - fortinet_fortigate - fortinet_fortimail - fortinet_fortimanager - fortinet_fortiproxy - goflow2 - hashicorp_vault - hpe_aruba_cx
@taylor-swanson taylor-swanson force-pushed the chore/event-original-part2 branch from c156c20 to 766916f Compare October 29, 2025 17:51
@elasticmachine
Copy link

💚 Build Succeeded

History

cc @taylor-swanson

@taylor-swanson taylor-swanson marked this pull request as ready for review November 4, 2025 21:18
@taylor-swanson taylor-swanson requested review from a team as code owners November 4, 2025 21:18
@elasticmachine
Copy link

Pinging @elastic/integration-experience (Team:Integration-Experience)

@andrewkroh andrewkroh added the Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform] label Nov 5, 2025
@elasticmachine
Copy link

Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform)

@taylor-swanson taylor-swanson merged commit 33de257 into elastic:main Nov 7, 2025
7 checks passed
@taylor-swanson taylor-swanson deleted the chore/event-original-part2 branch November 7, 2025 14:31
@elastic-vault-github-plugin-prod

Package citrix_waf - 1.19.0 containing this change is available at https://epr.elastic.co/package/citrix_waf/1.19.0/

@elastic-vault-github-plugin-prod

Package endace - 0.2.0 containing this change is available at https://epr.elastic.co/package/endace/0.2.0/

@elastic-vault-github-plugin-prod

Package fortinet_fortiedr - 1.20.0 containing this change is available at https://epr.elastic.co/package/fortinet_fortiedr/1.20.0/

@elastic-vault-github-plugin-prod

Package fortinet_fortigate - 1.36.0 containing this change is available at https://epr.elastic.co/package/fortinet_fortigate/1.36.0/

@elastic-vault-github-plugin-prod

Package fortinet_fortimail - 2.17.0 containing this change is available at https://epr.elastic.co/package/fortinet_fortimail/2.17.0/

@elastic-vault-github-plugin-prod

Package fortinet_fortimanager - 2.17.0 containing this change is available at https://epr.elastic.co/package/fortinet_fortimanager/2.17.0/

@elastic-vault-github-plugin-prod

Package fortinet_fortiproxy - 1.3.0 containing this change is available at https://epr.elastic.co/package/fortinet_fortiproxy/1.3.0/

@elastic-vault-github-plugin-prod

Package goflow2 - 0.6.0 containing this change is available at https://epr.elastic.co/package/goflow2/0.6.0/

@elastic-vault-github-plugin-prod

Package hashicorp_vault - 1.29.0 containing this change is available at https://epr.elastic.co/package/hashicorp_vault/1.29.0/

@elastic-vault-github-plugin-prod

Package hpe_aruba_cx - 0.2.0 containing this change is available at https://epr.elastic.co/package/hpe_aruba_cx/0.2.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:citrix_waf Citrix Web App Firewall Integration:endace Endace (Partner supported) Integration:fortinet_fortiedr Fortinet FortiEDR Logs Integration:fortinet_fortigate Fortinet FortiGate Firewall Logs Integration:fortinet_fortimail Fortinet FortiMail Integration:fortinet_fortimanager Fortinet FortiManager Logs Integration:fortinet_fortiproxy Fortinet FortiProxy Integration:goflow2 GoFlow2 logs (Community supported) Integration:hashicorp_vault Hashicorp Vault Integration:hpe_aruba_cx HPE Aruba CX Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience] Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform]

4 participants