Skip to content

Remove event.original processors from several remaining integrations part 1 - #13521

Merged
taylor-swanson merged 5 commits into
elastic:mainfrom
Alphayeeeet:remove-event.original5
May 6, 2025
Merged

Remove event.original processors from several remaining integrations part 1#13521
taylor-swanson merged 5 commits into
elastic:mainfrom
Alphayeeeet:remove-event.original5

Conversation

@Alphayeeeet

Copy link
Copy Markdown
Contributor

Label as enhancement

Proposed commit message

Remove event.original removal processors

Related issues

Review #10072 for additional info

@Alphayeeeet
Alphayeeeet requested review from a team as code owners April 12, 2025 10:31

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gcp LGTM

@efd6

efd6 commented Apr 13, 2025

Copy link
Copy Markdown
Contributor

/test

@elastic-vault-github-plugin-prod

elastic-vault-github-plugin-prod Bot commented Apr 13, 2025

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

Package golang 👍(0) 💚(0) 💔(2)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
expvar 4291.85 2570.69 -1721.16 (-40.1%) 💔
heap 3802.28 3174.6 -627.68 (-16.51%) 💔

Package hadoop 👍(2) 💚(1) 💔(2)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
cluster 5882.35 4784.69 -1097.66 (-18.66%) 💔
datanode 12987.01 10101.01 -2886 (-22.22%) 💔

Package hashicorp_vault 👍(1) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
log 10000 7751.94 -2248.06 (-22.48%) 💔

To see the full report comment with /test benchmark fullreport

@efd6

efd6 commented Apr 13, 2025

Copy link
Copy Markdown
Contributor

/test

@andrewkroh andrewkroh added Integration:hadoop Hadoop Integration:gcp Google Cloud Platform Integration:goflow2 GoFlow2 logs (Community supported) Integration:hid_bravura_monitor Bravura Monitor (Partner supported) Integration:microsoft_exchange_server Microsoft Exchange Server (Community supported) Integration:hashicorp_vault Hashicorp Vault Integration:imperva Imperva Integration:golang Golang Team:Obs-InfraObs Observability Infrastructure Monitoring team [elastic/obs-infraobs-integrations] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices] Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform] labels Apr 14, 2025
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)

@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)

@taylor-swanson taylor-swanson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

conditions:
kibana:
version: ^8.7.1 || ^9.0.0
version: ^8.11.0 || ^9.0.0

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why are we changing the version here ?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@ishleenk17 Same reason as pointed out in the next review. Please refer to that

conditions:
kibana:
version: "^8.10.1 || ^9.0.0"
version: "^8.11.0 || ^9.0.0"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why are we updating the kibana version ?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If it is beacuse the fleet addition of processor got added in this. I am not sure if its a good idea to upgrade the kibana version just to support that.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See #10072 (comment), this PR relies on the fleet final pipeline changes introduced in 8.11.0

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@ishleenk17 The reason is the point mentioned by @taylor-swanson

@Alphayeeeet
Alphayeeeet requested a review from ishleenk17 April 29, 2025 10:04
@Alphayeeeet

Copy link
Copy Markdown
Contributor Author

@efd6 @ishleenk17 @taylor-swanson @nfritts @andrewkroh Can please anyone run CI tests again and merge if applicable. Thank you

@ishleenk17

Copy link
Copy Markdown
Member

/test

@efd6

efd6 commented May 4, 2025

Copy link
Copy Markdown
Contributor

@Alphayeeeet It looks like you will need to regenerate the test expectations for hid_bravura_monitor.

@Alphayeeeet

Copy link
Copy Markdown
Contributor Author

@efd6 Done. Please run CI tests again

@andrewkroh

Copy link
Copy Markdown
Contributor

/test

@elastic-sonarqube

Copy link
Copy Markdown

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit only

# newer versions go on top
- version: "2.42.0"
changes:
- description: Allow @custom pipeline access to event.original without setting preserve_original_event.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- description: Allow @custom pipeline access to event.original without setting preserve_original_event.
- description: Allow `@custom` pipeline access to `event.original` without setting preserve_original_event.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe change to preserve_original_event too

@taylor-swanson
taylor-swanson merged commit 66883a6 into elastic:main May 6, 2025
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package gcp - 2.42.0 containing this change is available at https://epr.elastic.co/package/gcp/2.42.0/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package goflow2 - 0.5.0 containing this change is available at https://epr.elastic.co/package/goflow2/0.5.0/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package golang - 1.8.0 containing this change is available at https://epr.elastic.co/package/golang/1.8.0/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package hadoop - 1.9.0 containing this change is available at https://epr.elastic.co/package/hadoop/1.9.0/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package hashicorp_vault - 1.28.0 containing this change is available at https://epr.elastic.co/package/hashicorp_vault/1.28.0/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package hid_bravura_monitor - 1.21.0 containing this change is available at https://epr.elastic.co/package/hid_bravura_monitor/1.21.0/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package imperva - 1.6.0 containing this change is available at https://epr.elastic.co/package/imperva/1.6.0/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package microsoft_exchange_server - 1.4.0 containing this change is available at https://epr.elastic.co/package/microsoft_exchange_server/1.4.0/

@Alphayeeeet
Alphayeeeet deleted the remove-event.original5 branch July 14, 2025 06:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Integration:gcp Google Cloud Platform Integration:goflow2 GoFlow2 logs (Community supported) Integration:golang Golang Integration:hadoop Hadoop Integration:hashicorp_vault Hashicorp Vault Integration:hid_bravura_monitor Bravura Monitor (Partner supported) Integration:imperva Imperva Integration:microsoft_exchange_server Microsoft Exchange Server (Community supported) Team:Obs-InfraObs Observability Infrastructure Monitoring team [elastic/obs-infraobs-integrations] Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants