Skip to content

Commit ee62fa7

Browse files
[cisco_meraki] Update event.type and event.category of anyconnect_vpn_connect (elastic#14736)
1 parent 9dbd117 commit ee62fa7

File tree

4 files changed

+26
-5
lines changed

4 files changed

+26
-5
lines changed

packages/cisco_meraki/changelog.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
# newer versions go on top
2+
- version: "1.30.0"
3+
changes:
4+
- description: Update `event.type` and `event.category` of `anyconnect_vpn_connect`.
5+
type: enhancement
6+
link: https://github.com/elastic/integrations/pull/14736
27
- version: "1.29.2"
38
changes:
49
- description: Map translated source and destination IP and port to correct ECS fields.

packages/cisco_meraki/data_stream/log/_dev/test/pipeline/test-events.log-expected.json

Lines changed: 12 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1674,11 +1674,15 @@
16741674
"event": {
16751675
"action": "anyconnect_vpn_connect",
16761676
"category": [
1677-
"network"
1677+
"network",
1678+
"session"
16781679
],
16791680
"original": "<134>1 1639132851.416656563 TCP9001 events anyconnect_vpn_connect user id 'user.name2' local ip 172.25.22.244 reconnected from 67.43.156.14",
16801681
"type": [
1681-
"info"
1682+
"info",
1683+
"access",
1684+
"allowed",
1685+
"start"
16821686
]
16831687
},
16841688
"message": "user id 'user.name2' local ip 172.25.22.244 reconnected from 67.43.156.14",
@@ -1722,11 +1726,15 @@
17221726
"event": {
17231727
"action": "anyconnect_vpn_connect",
17241728
"category": [
1725-
"network"
1729+
"network",
1730+
"session"
17261731
],
17271732
"original": "<134>1 1639132851.416656563 TCP9001 events anyconnect_vpn_connect user id 'user.name3' local ip 175.16.199.1 connected from 1.128.0.1",
17281733
"type": [
1729-
"info"
1734+
"info",
1735+
"access",
1736+
"allowed",
1737+
"start"
17301738
]
17311739
},
17321740
"message": "user id 'user.name3' local ip 175.16.199.1 connected from 1.128.0.1",

packages/cisco_meraki/data_stream/log/elasticsearch/ingest_pipeline/default.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -85,6 +85,14 @@ processors:
8585
type:
8686
- access
8787
action: site-to-site-vpn
88+
"anyconnect_vpn_connect":
89+
category:
90+
- session
91+
type:
92+
- access
93+
- allowed
94+
- start
95+
action: anyconnect_vpn_connect
8896
"client_vpn_connect":
8997
category:
9098
- session

packages/cisco_meraki/manifest.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
format_version: "3.0.2"
22
name: cisco_meraki
33
title: Cisco Meraki
4-
version: "1.29.2"
4+
version: "1.30.0"
55
description: Collect logs from Cisco Meraki with Elastic Agent.
66
type: integration
77
categories:

0 commit comments

Comments
 (0)