[prisma_cloud] Add Dashboards for all the Data Streams and Update the Test Logs #8391
Add this suggestion to a batch that can be applied as a single commit. This suggestion is invalid because no changes were made to the code. Suggestions cannot be applied while the pull request is closed. Suggestions cannot be applied while viewing a subset of changes. Only one suggestion per line can be applied in a batch. Add this suggestion to a batch that can be applied as a single commit. Applying suggestions on deleted lines is not supported. You must change the existing code in this line in order to create a valid suggestion. Outdated suggestions cannot be applied. This suggestion has been applied or marked resolved. Suggestions cannot be applied from pending reviews. Suggestions cannot be applied on multi-line comments. Suggestions cannot be applied while the pull request is queued to merge. Suggestion cannot be applied right now. Please check back later.
Type of change
What does this PR do?
1. Add Support for the dashboards of all the data streams.
2. Update test logs for the incident audit data stream.
Previously we did not have the test data so we added
stringsin the fields, now we have updated the test logs.3. Change incident_audit.data.attack.techniques from nested array to array.
In the API Document, it is mentioned in the schema that this field would be a nested array but in the live responses we are
getting incident_audit.data.attack.techniques as an array so we have implemented this change.
4. Add one ECS mapping in the Incident Audit Data Stream.
Mapped os.full with the incident_audit.data.os.
Checklist
changelog.ymlfile.All changes
How to test this PR locally
Clone integrations repo.
Install the elastic package locally.
Start the elastic stack using the elastic package.
Move to integrations/packages/prisma_cloud directory.
Run the following command to run tests.
elastic-package test -vAutomated Test
test_logs.txt