Skip to content

Commit d51dd29

Browse files
authored
google_workspace,jamf_protect,ti_mandiant: add "preserve_original_event" tag to documents with event.kind set to "pipeline_error" (#12108)
This manually replays the changes in #12046.
1 parent 074b4ba commit d51dd29

File tree

25 files changed

+94
-3
lines changed

25 files changed

+94
-3
lines changed

packages/google_workspace/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "2.27.0"
3+
changes:
4+
- description: Add "preserve_original_event" tag to documents with `event.kind` set to "pipeline_error".
5+
type: enhancement
6+
link: https://github.com/elastic/integrations/pull/12108
27
- version: "2.26.1"
38
changes:
49
- description: Fix string literals in painless scripts.

packages/google_workspace/data_stream/access_transparency/elasticsearch/ingest_pipeline/default.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -382,3 +382,7 @@ on_failure:
382382
- set:
383383
field: event.kind
384384
value: pipeline_error
385+
- append:
386+
field: tags
387+
value: preserve_original_event
388+
allow_duplicates: false

packages/google_workspace/data_stream/admin/elasticsearch/ingest_pipeline/default.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -823,6 +823,10 @@ on_failure:
823823
- set:
824824
field: event.kind
825825
value: pipeline_error
826+
- append:
827+
field: tags
828+
value: preserve_original_event
829+
allow_duplicates: false
826830
- append:
827831
field: error.message
828832
value: '{{{ _ingest.on_failure_message }}}'

packages/google_workspace/data_stream/alert/elasticsearch/ingest_pipeline/default.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1056,6 +1056,10 @@ on_failure:
10561056
- set:
10571057
field: event.kind
10581058
value: pipeline_error
1059+
- append:
1060+
field: tags
1061+
value: preserve_original_event
1062+
allow_duplicates: false
10591063
- append:
10601064
field: error.message
10611065
value: '{{{ _ingest.on_failure_message }}}'

packages/google_workspace/data_stream/context_aware_access/elasticsearch/ingest_pipeline/default.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -357,3 +357,7 @@ on_failure:
357357
- set:
358358
field: event.kind
359359
value: pipeline_error
360+
- append:
361+
field: tags
362+
value: preserve_original_event
363+
allow_duplicates: false

packages/google_workspace/data_stream/device/elasticsearch/ingest_pipeline/default.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -554,3 +554,7 @@ on_failure:
554554
- set:
555555
field: event.kind
556556
value: pipeline_error
557+
- append:
558+
field: tags
559+
value: preserve_original_event
560+
allow_duplicates: false

packages/google_workspace/data_stream/drive/elasticsearch/ingest_pipeline/default.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -276,6 +276,10 @@ on_failure:
276276
- set:
277277
field: event.kind
278278
value: pipeline_error
279+
- append:
280+
field: tags
281+
value: preserve_original_event
282+
allow_duplicates: false
279283
- append:
280284
field: error.message
281285
value: '{{{ _ingest.on_failure_message }}}'

packages/google_workspace/data_stream/gcp/elasticsearch/ingest_pipeline/default.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -337,3 +337,7 @@ on_failure:
337337
- set:
338338
field: event.kind
339339
value: pipeline_error
340+
- append:
341+
field: tags
342+
value: preserve_original_event
343+
allow_duplicates: false

packages/google_workspace/data_stream/group_enterprise/elasticsearch/ingest_pipeline/default.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -377,3 +377,7 @@ on_failure:
377377
- set:
378378
field: event.kind
379379
value: pipeline_error
380+
- append:
381+
field: tags
382+
value: preserve_original_event
383+
allow_duplicates: false

packages/google_workspace/data_stream/groups/elasticsearch/ingest_pipeline/default.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -307,6 +307,10 @@ on_failure:
307307
- set:
308308
field: event.kind
309309
value: pipeline_error
310+
- append:
311+
field: tags
312+
value: preserve_original_event
313+
allow_duplicates: false
310314
- append:
311315
field: error.message
312316
value: '{{{ _ingest.on_failure_message }}}'

0 commit comments

Comments
 (0)