[google_secops] Add Alert v2 Data Stream and Deprecate Alert Data Stream#20258
[google_secops] Add Alert v2 Data Stream and Deprecate Alert Data Stream#20258mohitjha-elastic wants to merge 2 commits into
Conversation
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
Elastic Docs Style Checker (Vale)Summary: 52 warnings, 3 suggestions found
|
| File | Line | Rule | Message |
|---|---|---|---|
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 87 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 87 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 108 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 183 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 183 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 261 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 261 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 261 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 321 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 321 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 324 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 336 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 366 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 366 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 466 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 505 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 538 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 571 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 604 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 610 | Elastic.DontUse | Don't use 'Please'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 616 | Elastic.DontUse | Don't use 'Please'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 622 | Elastic.DontUse | Don't use 'Please'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 628 | Elastic.DontUse | Don't use 'Please'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 634 | Elastic.DontUse | Don't use 'Please'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 676 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 682 | Elastic.DontUse | Don't use 'Please'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 691 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 694 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 712 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 712 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 737 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 758 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 761 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 805 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 808 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 827 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 837 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 849 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 858 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 858 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 909 | Elastic.DontUse | Don't use 'Please'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 918 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 930 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 990 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 990 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 1045 | Elastic.DontUse | Don't use 'Please'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 1051 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 1054 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 1057 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 1100 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 1103 | Elastic.Latinisms | Latin terms and abbreviations are a common source of confusion. Use 'for example' instead of 'e.g'. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 1115 | Elastic.QuotesPunctuation | Place punctuation inside closing quotation marks. |
💡 Suggestions (3): Optional style improvements. Apply when helpful.
| File | Line | Rule | Message |
|---|---|---|---|
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 16 | Elastic.WordChoice | Consider using 'deactivated, deselected, hidden, turned off, unavailable' instead of 'disabled', unless the term is in the UI. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 691 | Elastic.Ellipses | In general, don't use an ellipsis. |
| packages/google_secops/data_stream/alert_v2/fields/fields.yml | 1051 | Elastic.Ellipses | In general, don't use an ellipsis. |
The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.
|
✅ All changelog entries have the correct PR link. |
🚀 Benchmarks reportTo see the full report comment with |
💚 Build Succeeded
|
| description: Outcome variables from the detection rule, keyed by outcome name. | ||
| - name: risk_score | ||
| type: long | ||
| - name: risk_score |
There was a problem hiding this comment.
Severity: 🟠 High confidence: high path: packages/google_secops/data_stream/alert_v2/fields/fields.yml:28
detection.risk_score is defined twice with conflicting types (long then group) in fields.yml; remove the spurious group block so the field is only declared once as long.
Details
Within the detection group, risk_score is declared twice: first as a scalar type: long (line 26-27) and immediately again as an object type: group with int64_val/type/value sub-fields (line 28-36). A field cannot be both a scalar long leaf and an object, so this is a mapping conflict and a duplicate field definition that elastic-package check rejects. The group block is a copy of the detection.variables.risk_score structure defined later in the same file (line 55-66); nothing in the ingest pipeline writes detection.risk_score.int64_val/type/value — the pipeline converts the scalar detection.*.risk_score to long (tag convert_detection_risk_score_to_long) and later removes it, and the expected test output shows detection.risk_score only ever as a scalar. The object variant is therefore both invalid and unused.
Recommendation:
Keep the single scalar declaration and delete the duplicate group block:
- name: risk_score
type: long
- name: rule_id
type: keyword
description: "Identifier for the rule generating the detection."🤖 AI-Generated Review | Vera Review Bot | 📚 Knowledge base: integration-skills
⚠️ Automated review — verify suggestions before applying.
Review summaryIssues found across the latest commits 80ea385 — 1 high
🤖 AI-Generated Review | Vera Review Bot | 📚 Knowledge base: integration-skills
|
There was a problem hiding this comment.
There are a large number of uninformative fields in the test input, for example the large array of {"string": "string"} objects, but not limited to that; if the field is not the basis for logic, it does not need to be tested multiple times and if it's an array, unless the length is the subject of a logical decision, it does not need to be long. Can we reduce the inputs to just include test-informative fields.
| ?"next_page": has(body.nextPageToken) ? | ||
| optional.of({ | ||
| "token": body.nextPageToken, | ||
| }) | ||
| : | ||
| optional.none(), |
There was a problem hiding this comment.
| ?"next_page": has(body.nextPageToken) ? | |
| optional.of({ | |
| "token": body.nextPageToken, | |
| }) | |
| : | |
| optional.none(), | |
| ?"next_page": body.?nextPageToken.optMap(t, {"token": t}), |
| "startTime": [string(state.cursor.start_time)], | ||
| "endTime": [string(state.cursor.end_time)], |
There was a problem hiding this comment.
| "startTime": [string(state.cursor.start_time)], | |
| "endTime": [string(state.cursor.end_time)], | |
| "startTime": [state.cursor.start_time], | |
| "endTime": [state.cursor.end_time], |
These are already strings.
| d.?collectionElements.orValue([]).map(ce, | ||
| ce.?references.orValue([]).map(result, { |
There was a problem hiding this comment.
| d.?collectionElements.orValue([]).map(ce, | |
| ce.?references.orValue([]).map(result, { | |
| d.?collectionElements.orValue([]).map(ce, has(ce.references), | |
| ce.references.map(result, { |
| "events": { | ||
| "error": { | ||
| "code": string(resp.StatusCode), | ||
| "id": string(resp.Status), |
There was a problem hiding this comment.
| "id": string(resp.Status), | |
| "id": resp.Status, |
| size(resp.Body) != 0 ? | ||
| string(resp.Body) | ||
| : | ||
| string(resp.Status) + ' (' + string(resp.StatusCode) + ')' |
There was a problem hiding this comment.
| string(resp.Status) + ' (' + string(resp.StatusCode) + ')' | |
| resp.Status + ' (' + string(resp.StatusCode) + ')' |
| if (list["severity"].toUpperCase() == 'CRITICAL') { | ||
| ctx.event.severity = 99 | ||
| } else if (list["severity"].toUpperCase() == 'ERROR') { | ||
| ctx.event.severity = 99 | ||
| } else if (list["severity"].toUpperCase() == 'HIGH') { | ||
| ctx.event.severity = 73 | ||
| } else if (list["severity"].toUpperCase() == 'INFORMATIONAL') { | ||
| ctx.event.severity = 21 | ||
| } else if (list["severity"].toUpperCase() == 'LOW') { | ||
| ctx.event.severity = 21 | ||
| } else if (list["severity"].toUpperCase() == 'MEDIUM') { | ||
| ctx.event.severity = 47 | ||
| } else if (list["severity"].toUpperCase() == 'NONE') { | ||
| ctx.event.severity = 21 | ||
| } else if (list["severity"].toUpperCase() == 'UNKNOWN_SEVERITY') { |
There was a problem hiding this comment.
Use case-insensitive comparison; equalsIgnoreCase.
| if (list["severity"].toUpperCase() == 'CRITICAL') { | |
| ctx.event.severity = 99 | |
| } else if (list["severity"].toUpperCase() == 'ERROR') { | |
| ctx.event.severity = 99 | |
| } else if (list["severity"].toUpperCase() == 'HIGH') { | |
| ctx.event.severity = 73 | |
| } else if (list["severity"].toUpperCase() == 'INFORMATIONAL') { | |
| ctx.event.severity = 21 | |
| } else if (list["severity"].toUpperCase() == 'LOW') { | |
| ctx.event.severity = 21 | |
| } else if (list["severity"].toUpperCase() == 'MEDIUM') { | |
| ctx.event.severity = 47 | |
| } else if (list["severity"].toUpperCase() == 'NONE') { | |
| ctx.event.severity = 21 | |
| } else if (list["severity"].toUpperCase() == 'UNKNOWN_SEVERITY') { | |
| if (list["severity"].equalsIgnoreCase('critical')) { | |
| ctx.event.severity = 99 | |
| } else if (list["severity"].equalsIgnoreCase('error')) { | |
| ctx.event.severity = 99 | |
| } else if (list["severity"].equalsIgnoreCase('high')) { | |
| ctx.event.severity = 73 | |
| } else if (list["severity"].equalsIgnoreCase('informational')) { | |
| ctx.event.severity = 21 | |
| } else if (list["severity"].equalsIgnoreCase('low')) { | |
| ctx.event.severity = 21 | |
| } else if (list["severity"].equalsIgnoreCase('medium')) { | |
| ctx.event.severity = 47 | |
| } else if (list["severity"].equalsIgnoreCase('none')) { | |
| ctx.event.severity = 21 | |
| } else if (list["severity"].equalsIgnoreCase('unknown_severity')) { |
| "y": 58 | ||
| }, | ||
| "panelIndex": "0c26cc51-158d-48f2-bb23-8f996391fb3d", | ||
| "title": "Top 10 Destination IP ", |
There was a problem hiding this comment.
| "title": "Top 10 Destination IP ", | |
| "title": "Top 10 Destination IP", |
| }, | ||
| "panelIndex": "22679e22-be09-4425-9b59-4f26d23fc230", | ||
| "panelRefName": "panel_22679e22-be09-4425-9b59-4f26d23fc230", | ||
| "title": "Rule Essential Details [Logs Google SecOps]", |
There was a problem hiding this comment.
| "title": "Rule Essential Details [Logs Google SecOps]", | |
| "title": "Rule Essential Details", |
Maybe do a clean up of these throughout.
Proposed commit message
Checklist
changelog.ymlfile.How to test this PR locally
Related Issues