Skip to content

Commit 9dbd117

Browse files
authored
Update PAD and LMD transform mappings to ECS (#14696)
* update transform mappings to ecs * add build.yml * update changelog and manifests * fix package version in changelog * bump fleet transform versions
1 parent b562724 commit 9dbd117

File tree

12 files changed

+49
-33
lines changed

12 files changed

+49
-33
lines changed

packages/lmd/_dev/build/build.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
dependencies:
2+
ecs:
3+
reference: "[email protected]"

packages/lmd/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "2.5.2"
3+
changes:
4+
- description: Update transform mappings to use ECS
5+
type: enhancement
6+
link: https://github.com/elastic/integrations/pull/14696
27
- version: "2.5.1"
38
changes:
49
- description: Update platform support docs

packages/lmd/elasticsearch/transform/pivot_transform/fields/fields.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
1-
- name: host.name
2-
type: keyword
3-
- name: user.name
4-
type: keyword
1+
- external: ecs
2+
name: host.name
3+
- external: ecs
4+
name: user.name
55
- name: process.Ext.authentication_id
66
type: keyword
7-
- name: destination.ip
8-
type: ip
9-
- name: source.ip
10-
type: ip
7+
- external: ecs
8+
name: destination.ip
9+
- external: ecs
10+
name: source.ip
1111
- name: session.start_time
1212
type: date
1313
- name: session.complete_time

packages/lmd/elasticsearch/transform/pivot_transform/transform.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -75,5 +75,5 @@ sync:
7575
delay: 60s
7676
field: '@timestamp'
7777
_meta:
78-
fleet_transform_version: 2.4.0
78+
fleet_transform_version: 2.4.1
7979
run_as_kibana_system: false

packages/lmd/manifest.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
format_version: 3.0.0
22
name: lmd
33
title: "Lateral Movement Detection"
4-
version: 2.5.1
4+
version: 2.5.2
55
source:
66
license: "Elastic-2.0"
77
description: "ML package to detect lateral movement based on file transfer activity and Windows RDP events."

packages/pad/_dev/build/build.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
dependencies:
2+
ecs:
3+
reference: "[email protected]"

packages/pad/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,8 @@
1+
- version: "0.6.2"
2+
changes:
3+
- description: Update transform mappings to use ECS
4+
type: enhancement
5+
link: https://github.com/elastic/integrations/pull/14696
16
- version: "0.6.1"
27
changes:
38
- description: Update platform support docs
Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
1-
- name: source.user.name
2-
type: keyword
3-
- name: source.user.full_name
4-
type: keyword
1+
- external: ecs
2+
name: source.user.name
3+
- external: ecs
4+
name: source.user.full_name
55
- name: okta_distinct_ips
66
type: long
77
- name: okta_distinct_countries
88
type: long
99
- name: okta_session_info.has_end_event
1010
type: long
11-
- name: agent.name
12-
type: keyword
13-
- name: '@timestamp'
14-
type: date
11+
- external: ecs
12+
name: agent.name
13+
- external: ecs
14+
name: '@timestamp'

packages/pad/elasticsearch/transform/pivot_transform_okta_multiple_sessions/transform.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,5 +58,5 @@ sync:
5858
delay: 60s
5959
field: '@timestamp'
6060
_meta:
61-
fleet_transform_version: 0.0.1
61+
fleet_transform_version: 0.0.2
6262
run_as_kibana_system: false
Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
1-
- name: host.name
2-
type: keyword
3-
- name: user.name
4-
type: keyword
1+
- external: ecs
2+
name: host.name
3+
- external: ecs
4+
name: user.name
55
- name: privilege_type
66
type: keyword
7-
- name: event.action
8-
type: keyword
9-
- name: event.code
10-
type: keyword
11-
- name: event.category
12-
type: keyword
13-
- name: '@timestamp'
14-
type: date
7+
- external: ecs
8+
name: event.action
9+
- external: ecs
10+
name: event.code
11+
- external: ecs
12+
name: event.category
13+
- external: ecs
14+
name: '@timestamp'

0 commit comments

Comments
 (0)