Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FR] Redesign Filed Mapping Check for Integration Packages #4006

Open
shashank-elastic opened this issue Aug 22, 2024 · 0 comments
Open

[FR] Redesign Filed Mapping Check for Integration Packages #4006

shashank-elastic opened this issue Aug 22, 2024 · 0 comments
Assignees
Labels

Comments

@shashank-elastic
Copy link
Contributor

Repository Feature

Core Repo - (rule management, validation, testing, lib, cicd, etc.)

Problem Description

When fileds.yml was removed in version 2.0.3 of DGA as part of the PR, in the current design of our unit tests, we pull any YML field files for all integrations to do integration specific field validation within our queries, Refer making the tests dependent on static mappings somewhere.

Desired Solution

  • Ideate on Possible ways to move from the static mapping of the fields.
    << TBD >>

Considered Alternatives

Currently for the Integrations tests to pass, DGA package was regenerated with the field mappings via https://github.com/elastic/security-ml/issues/474.

Additional Context

The ML team has a concern leaving the yaml files with the fields in these packages because it gives the illusion that the field mapping issue with them is already solved. The ML team has another issue open to try to help with the issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants