elastic / elastic/integrations

[Anthropic]: Audit Overview Dashboard - Panel data incorrect

Open Beginner friendly
#20,881 1 comment 0 reactions 0 assignees View on GitHub
bug Integration:anthropic needs:triage Team:Security-Service Integrations
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

### Integration Name

Anthropic [packages/anthropic]

### Dataset Name

anthropic.audit

### Integration Version

1.1.0

### Agent Version

9.5.1

### Agent Output Type

elasticsearch

### Elasticsearch Version

9.5.1

### OS Version and Architecture

MacOS

### Software/API Version

_No response_

### Error Message

_No response_

### Event Original

_No response_

### What did you do?

Open the [Logs Anthropic] Audit Overview dashboard and review the Top Related IPs dashboard panel.

### What did you see?

This dashboard panel is a duplicate of Top Actors and aggregates based on user.name rather than an IP address.

### What did you expect to see?

This dashboard should have IP addresses not Actors as the aggregate field.

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Research direction

Start with the Anthropic integration's Logs Anthropic Audit Overview dashboard and compare the Top Related IPs panel with Top Actors. Confirm which field each panel aggregates, then update the panel so it uses an IP address field and verify that the displayed values are IP addresses rather than actors.

Written by the indexing model from the issue text.

Assessment

Tech stack
elasticsearch
Domain
observability
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
74/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.