elastic / elastic/integrations
[Subscription basic] [cloudflare_logpush] Failing test daily: policy test: test-aws-s3.yml in cloudflare_logpush.email_security_alerts
- Dominant language
- Handlebars
- Stars
- 333
- Forks
- 647
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 209
Description
- Stack version: Same as in Pull Request builds
- Subscription: basic
- Package: cloudflare_logpush
- Failing test: policy test: test-aws-s3.yml
- DataStream: email_security_alerts
- Owners:
- @elastic/security-service-integrations
- @elastic/sit-crest-contractors
Error:
```
cleanup failed: there was an apply error: could not delete policy "test-aws-s3-76673": could not delete policy; API status code = 400; response body = {"statusCode":400,"error":"Bad Request","message":"KQLSyntaxError: Expected \")\" but \"N\" found.\ningest-package-policies.attributes.secret_references.id: (Wf85RZ8Bg9k13wUkANoR or W_85RZ8Bg9k13wUkANoT or Wv85RZ8Bg9k13wUkANoR)\n---------------------------------------------------------------------------------------------------^: Bad Request"}
```
First build failed: https://buildkite.com/elastic/integrations/builds/45770
Contributor guide
Research direction
Start by running the policy test in test-aws-s3.yml for the cloudflare_logpush package and review the cleanup failure for the email_security_alerts data stream. Trace why deleting policy test-aws-76673 produces the KQLSyntaxError, then confirm the test completes successfully, including cleanup.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, yaml
- Domain
- cloud, testing
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100