Skip to content

[Exchange Server] Add conditional override when from address differs from sender address & minor enhancements - #11002

Merged
marc-gr merged 5 commits into
elastic:mainfrom
SimonKoetting:exchange_pr
Sep 5, 2024
Merged

[Exchange Server] Add conditional override when from address differs from sender address & minor enhancements#11002
marc-gr merged 5 commits into
elastic:mainfrom
SimonKoetting:exchange_pr

Conversation

@SimonKoetting

@SimonKoetting SimonKoetting commented Sep 4, 2024

Copy link
Copy Markdown
Contributor

[Exchange Server] Add conditional override when from address differs from sender address & minor enhancements

Minor enhancements:
switched to copy_from instead of using {{{}}} in set
tag preserve_original_event where ignored so far
adjust email.local_id to use network-message-id, as this is a unique ID and ECS requires a unique ID

Modifying email.from.address in case header includes a different mail then was used (e.g. ticket system sending on behalf of a user)

@andrewkroh andrewkroh added enhancement New feature or request Integration:microsoft_exchange_server Microsoft Exchange Server (Community supported) labels Sep 4, 2024
@elasticmachine

Copy link
Copy Markdown

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elastic-sonarqube

Copy link
Copy Markdown

Quality Gate failed Quality Gate failed

Failed conditions
52.4% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

@SimonKoetting
SimonKoetting marked this pull request as ready for review September 4, 2024 15:13
@SimonKoetting
SimonKoetting requested a review from a team as a code owner September 4, 2024 15:13
@andrewkroh andrewkroh added the Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform] label Sep 4, 2024
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)

@marc-gr
marc-gr merged commit a3c56d4 into elastic:main Sep 5, 2024
@elasticmachine

Copy link
Copy Markdown

Package microsoft_exchange_server - 1.1.0 containing this change is available at https://epr.elastic.co/search?package=microsoft_exchange_server

harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 4, 2025
…from sender address & minor enhancements (elastic#11002)

* change mustache set to copy_from

* add conditional deletion of event.original

* change email.local_id to be generated from network-message-id

* add conditional override of originalfrom address

* prepare PR
harnish-crest-data pushed a commit to chavdaharnish/integrations that referenced this pull request Feb 5, 2025
…from sender address & minor enhancements (elastic#11002)

* change mustache set to copy_from

* add conditional deletion of event.original

* change email.local_id to be generated from network-message-id

* add conditional override of originalfrom address

* prepare PR
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:microsoft_exchange_server Microsoft Exchange Server (Community supported) Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants