elastic / elastic/integrations

[Subscription basic] [cloudflare_logpush] Failing test daily: policy test: test-aws-s3.yml in cloudflare_logpush.email_security_alerts

Open
#20,054 1 comment 0 reactions 0 assignees View on GitHub
automation flaky-test Integration:cloudflare_logpush Team:Security-Service Integrations
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

- Stack version: Same as in Pull Request builds
- Subscription: basic
- Package: cloudflare_logpush
- Failing test: policy test: test-aws-s3.yml
- DataStream: email_security_alerts
- Owners:
- @elastic/security-service-integrations
- @elastic/sit-crest-contractors

Error:
```
cleanup failed: there was an apply error: could not delete policy "test-aws-s3-76673": could not delete policy; API status code = 400; response body = {"statusCode":400,"error":"Bad Request","message":"KQLSyntaxError: Expected \")\" but \"N\" found.\ningest-package-policies.attributes.secret_references.id: (Wf85RZ8Bg9k13wUkANoR or W_85RZ8Bg9k13wUkANoT or Wv85RZ8Bg9k13wUkANoR)\n---------------------------------------------------------------------------------------------------^: Bad Request"}
```

First build failed: https://buildkite.com/elastic/integrations/builds/45770

Contributor guide

Open the contributing guide

Research direction

Start by running the policy test in test-aws-s3.yml for the cloudflare_logpush package and review the cleanup failure for the email_security_alerts data stream. Trace why deleting policy test-aws-76673 produces the KQLSyntaxError, then confirm the test completes successfully, including cleanup.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, yaml
Domain
cloud, testing
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.