Skip to content

[meta] ECS 8.3 Updates (Security External Integrations) #3200

Description

@andrewkroh

This is a meta issue to track ECS 8.3 updates to Fleet integrations maintained by the elastic/security-external-integrations team.

ECS 8.3 Changes

This is a summary of the changes in ECS 8.3. You can view the official changelog here.

Added

  • Added pattern attribute to .mac fields.
  • Add orchestrator.cluster.id
  • Add orchestrator.resource.id

SEI owned Integrations

All integrations are updated in #3353. Separate PRs were merged to correct packages that were not formatting MACs as expected and these could be merged since this was already part of ECS prior to 8.3.

Integrations SEI contributes to

I reviewed these to see if they were affected any changes to ECS. None of them were affected so I didn't open a PR.

  • aws.cloudtrail
  • aws.vpcflow
  • system.application
  • system.auth
  • system.security
  • system.system
  • windows.forwarded
  • windows.powershell
  • windows.powershell_operational
  • windows.sysmon_operational

Activity

  1. self-assigned this
    on Apr 26, 2022
  2. elasticmachine commented on Apr 26, 2022

    @elasticmachine

    Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

  3. andrewkroh commented on May 6, 2022

    @andrewkroh
    ContributorAuthor

    It's going to be difficult to implement the MAC address formatting because there are parts of Beats producing these fields.

    • Modify Beats to format the MACs before sending.

      • The code change is rather simple. andrewkroh/beats@0bbcb1f
      • Impacts Beat users. IMO we only want to impact Agent data.
      • Doesn't fix the problem for older Agent versions. Integration system tests use 7.17 in a lot of cases.
        • We could raise the required stack version to ^8.3.0.
    • Add a processor to the Fleet final pipeline.

      • Adds unnecessary processing costs to some integrations.
      • Not all data ingestion paths should be subjected to ECS rules.
    • Have Agent inject a Beat processor into the Beat configuration to format the MAC.

      • Does not fix data coming from older Agent versions.
    • Modify every integration that uses add_host_metadata to have an ingest node processor to format host.mac.

      • Touches a lot of integrations.
      • This is only option that I think will work given the constraints. Going forward the inputs and processors in Agent v2 should switch to the ECS mac address format.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions