Repository navigation
SSI: Standardize processor tagging and event.original preservation across owned pipelines #20558
Copy link
Copy link
Closed
Closed
Enhancement
Copy link
Labels
Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request
Description
Activity
- added 12 commits that reference this issue
on Aug 6, 2026 - addedenhancementNew feature or requestNew feature or requestTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]
on Aug 18, 2026 infra-vault-gh-plugin-prod commented
on Aug 18, 2026 More actionsPinging @elastic/security-service-integrations (Team:Security-Service Integrations)
- added a commit that references this issue
on Aug 18, 2026 This is being addressed in four PRs, split alphabetically across the 169 SSI-owned packages:
PR Packages Processors tagged Pipeline files #20572 (1/4) 1password → entityanalytics_entra_id (51 pkgs) 25,752 303 #20573 (2/4) eset_protect → sentinel_one_cloud_funnel (51 pkgs) 24,011 341 #20574 (3/4) servicenow → zscaler_zpa (52 pkgs) 20,605 265 #20575 (4/4) final batch (15 pkgs) 3,724 42 Each PR tags every processor (including those nested inside
on_failurehandlers,foreachbodies, and pipeline-levelon_failureblocks), addspreserve_original_eventto pipeline-levelon_failureblocks that were missing it, and takes a minor version bump per package.Closing as completed.
Metadata
Metadata
Assignees
Labels
Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]enhancementNew feature or requestNew feature or request
Context
Diagnosing ingest-pipeline failures from telemetry depends on two conventions being applied consistently: every processor carrying a
tag, andevent.originalbeing preserved on failure. A scan of the 191 packages owned byelastic/security-service-integrationsshows both are applied unevenly. This issue tracks bringing the whole set up to standard; it generalizes the GA-candidate work in #20557.1. Processor tagging
Failure telemetry identifies a processor as
type:tag, or a baretypewhen untagged. Untagged same-type processors collapse into one bucket, so failures cannot be attributed to a specific step.Current state across 191 packages: 69% of processors tagged in aggregate.
carbonblack_edr,cylance,jamf_compliance_reporter,jamf_protect,lumos,lyve_cloudinfoblox_bloxone_ddi(1%),sophos_central(1%),atlassian_confluence(2%),carbon_black_cloud(2%),darktrace(2%),mattermost(2%),santa(2%),tenable_sc(2%),thycotic_ss(2%),ti_eclecticiq(2%),ti_mandiant_advantage(2%),1password(3%),bbot(3%),lastpass(3%),proofpoint_tap(3%),zerofox(3%),zscaler_zpa(3%), … (full list in the scan output).Target: every failure-capable processor carries a unique descriptive
tag.2. event.original preservation on failure
Of 797 pipelines with an
on_failureblock, roughly a quarter do not referencepreserve_original_event, meaning a failure may not retain the raw payload for diagnosis. Ordering bugs also exist whereevent.originalis removed before the failure point (seebitsightin ).Target: every pipeline's
on_failuresetsevent.kind: pipeline_error, appendspreserve_original_eventtotags, and appends processor context toerror.message; andevent.originalis populated before, and not removed ahead of, any processor that can fail.Suggested approach
event.originalpreservation; worth reusing here.elastic-packagecan add tags using:elastic-package modify -m pipeline-tagpreserve_original_eventinon_failure).Measurement
Numbers above are from parsing top-level processors in
packages/*/data_stream/*/elasticsearch/ingest_pipeline/*.ymlonmain. Percentages exclude processors nested insideforeach/on_failure, and theevent.originalfigure is a heuristic — treat per-package status as a starting point to verify, not a certification.