elastic / elastic/detection-rules

[Investigate] Redesign Filed Mapping Check for Integration Packages

Open
#4,006 0 comments 0 reactions 1 assignee Assigned to @traut View on GitHub
backlog enhancement Team: TRADE
Dominant language
Python
Stars
2.7k
Forks
696
Avg merge
4d 17h
Merged PRs (30d)
87

Description

### Repository Feature

Core Repo - (rule management, validation, testing, lib, cicd, etc.)

### Problem Description

When fileds.yml was removed in version 2.0.3 of DGA as part of the [PR](https://github.com/elastic/integrations/pull/10476), in the current design of our unit tests, we pull any YML field files for all integrations to do integration specific field validation within our queries, [Refer](https://github.com/elastic/detection-rules/blob/10ba6ad5a636b510dea9b1440ab5a30c2aff2dd5/detection_rules/integrations.py#L146) making the tests dependent on static mappings somewhere.

### Desired Solution

- Ideate on Possible ways to move from the static mapping of the fields.
<< TBD >>

### Considered Alternatives

Currently for the Integrations tests to pass, DGA package was regenerated with the field mappings via https://github.com/elastic/security-ml/issues/474.

### Additional Context

The ML team has a concern leaving the yaml files with the fields in these packages because it gives the illusion that the field mapping issue with them is already solved. The ML team has another [issue](https://github.com/elastic/package-spec/issues/778) open to try to help with the issue.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.