Skip to content

Conversation

@chrisberkhout
Copy link
Contributor

@chrisberkhout chrisberkhout commented Dec 31, 2025

Proposed commit message

[cyberarkpas] Handle syslog header in the monitor data stream

This matches the handling in the audit data stream, and should work with
or without the syslog header.

To make tests pass, an unrelated change was required: updating
timestamps in some audit data stream pipeline test expected outputs.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

@chrisberkhout chrisberkhout self-assigned this Dec 31, 2025
@chrisberkhout chrisberkhout requested a review from a team as a code owner December 31, 2025 10:07
@chrisberkhout chrisberkhout added enhancement New feature or request Integration:cyberarkpas CyberArk Privileged Access Security Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Dec 31, 2025
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod
Copy link

elastic-vault-github-plugin-prod bot commented Dec 31, 2025

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

Copy link
Contributor

@ShourieG ShourieG left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we add a test with syslog headers present ?

@chrisberkhout
Copy link
Contributor Author

Can we add a test with syslog headers present ?

👍 in new commit.

@chrisberkhout chrisberkhout requested a review from ShourieG January 2, 2026 09:13
@chrisberkhout chrisberkhout enabled auto-merge (squash) January 2, 2026 09:13
Copy link
Contributor

@ShourieG ShourieG left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ShourieG
Copy link
Contributor

ShourieG commented Jan 5, 2026

I think the tests need to be regenerated to fix the timestamp mismatch

@chrisberkhout chrisberkhout force-pushed the cyberarkpas-syslog-prefix branch from 0112200 to 4895fac Compare January 5, 2026 09:47
@chrisberkhout chrisberkhout disabled auto-merge January 5, 2026 09:47
@chrisberkhout chrisberkhout enabled auto-merge (squash) January 5, 2026 09:47
@elasticmachine
Copy link

💚 Build Succeeded

History

cc @chrisberkhout

@chrisberkhout chrisberkhout merged commit 91c522c into elastic:main Jan 5, 2026
8 checks passed
@elastic-vault-github-plugin-prod

Package cyberarkpas - 2.28.0 containing this change is available at https://epr.elastic.co/package/cyberarkpas/2.28.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:cyberarkpas CyberArk Privileged Access Security Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants