-
Notifications
You must be signed in to change notification settings - Fork 72
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] Get Mappings View API incorrectly returns ECS path for OCSF fields #866
Labels
bug
Something isn't working
Comments
5 tasks
riysaxen-amzn
pushed a commit
to riysaxen-amzn/security-analytics
that referenced
this issue
Mar 25, 2024
…cution (opensearch-project#849) (opensearch-project#866) * Update config index schema if needed at the start of each monitor execution Signed-off-by: Ashish Agrawal <[email protected]> (cherry picked from commit 21aeb3c001bb5cb9f4e698df203d9d96fc07a2d6) Co-authored-by: Ashish Agrawal <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
What is the bug?
SAP queries are not transformed correctly (with index name and monitor id) when the field in the index is not mapped correctly. There is a bug when a custom rule is created with a raw field name and an index with either raw fields or ocsf fields. The mappings view API returns the ecs name in the alias path instead of the correct ocsf or raw field name even when the ecs format is not present in the index.
How can one reproduce the bug?
Steps to reproduce the behavior:
What is the expected behavior?
The mappings view API should return the ocsf or the raw field path if a new rule is created using a raw field.
What is your host/environment?
Do you have any screenshots?
If applicable, add screenshots to help explain your problem.
Do you have any additional context?
Add any other context about the problem.
The text was updated successfully, but these errors were encountered: