Skip to content

pps: handle RFC 6587 octet-counting prefix and fix grok patterns - #17678

Merged
kcreddy merged 2 commits into
elastic:mainfrom
kcreddy:pps-octet-length
Mar 6, 2026
Merged

kcreddy merged 2 commits into
elastic:mainfrom
kcreddy:pps-octet-length

Conversation

@kcreddy

@kcreddy kcreddy commented Mar 5, 2026 •

Copy link
Copy Markdown
Contributor

Proposed commit message

pps: handle RFC 6587 octet-counting prefix and fix grok patterns

Newer versions of Pleasant Password Server prepend an RFC 6587
octet count (e.g. "230 ") to syslog messages sent over TCP. The
ingest pipeline's grok patterns anchored to "^<" and rejected
these messages, causing all fields to fall through to the
catch-all pattern.

Add an optional "\d+ " prefix to the two structured grok patterns
so they handle both formats without configuration changes.

Also fix three secondary grok patterns that used character classes
([created|updated], [from|to]) instead of alternation groups
((?:created|updated), (?:from|to)). These matched by accident
because the first character of each word was in the class, but
would not match the intended words correctly.

Expose a tcp_options variable on the TCP input so users can set
framing, max_message_size, or other TCP-level options if needed.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Author's Checklist

  • [ ]

How to test this PR locally

  • Added new pipeline test log samples mocked from earlier ones but containing the RFC6587 octet-counting prefix.
  • Pipeline tests pass
--- Test results for package: pps - START ---
╭─────────┬─────────────┬───────────┬───────────────────────────────────────────────────────┬────────┬──────────────╮
│ PACKAGE │ DATA STREAM │ TEST TYPE │ TEST NAME                                             │ RESULT │ TIME ELAPSED │
├─────────┼─────────────┼───────────┼───────────────────────────────────────────────────────┼────────┼──────────────┤
│ pps     │ log         │ pipeline  │ (ingest pipeline warnings test-log-octet-counted.log) │ PASS   │ 523.825084ms │
│ pps     │ log         │ pipeline  │ (ingest pipeline warnings test-log.log)               │ PASS   │ 370.010667ms │
│ pps     │ log         │ pipeline  │ test-log-octet-counted.log                            │ PASS   │   80.66225ms │
│ pps     │ log         │ pipeline  │ test-log.log                                          │ PASS   │ 100.978667ms │
╰─────────┴─────────────┴───────────┴───────────────────────────────────────────────────────┴────────┴──────────────╯
--- Test results for package: pps - END   ---
Done

Related issues

@kcreddy kcreddy self-assigned this Mar 5, 2026
@kcreddy kcreddy added enhancement New feature or request bugfix Pull request that fixes a bug issue Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Integration:pps Pleasant Password Server (Community supported) labels Mar 5, 2026
@kcreddy
kcreddy marked this pull request as ready for review March 5, 2026 10:35
@kcreddy
kcreddy requested a review from a team as a code owner March 5, 2026 10:35
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

cc @kcreddy

@kcreddy
kcreddy merged commit 2429e1f into elastic:main Mar 6, 2026
13 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package pps - 1.2.0 containing this change is available at https://epr.elastic.co/package/pps/1.2.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue enhancement New feature or request Integration:pps Pleasant Password Server (Community supported) Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants