Closed ar3diu closed 3 months ago
❌ Author of the following commits did not sign a Contributor Agreement: cc150efbde95db42a21c5bebd0dc74cc177c2089
Please, read and sign the above mentioned agreement if you want to contribute to this project
Issues
3803
Summary
Without a host grouping in the sequence of events, this rule triggers on events from different hosts which is not exactly the desired result.
thanks for flagging this, adjusted you PR to use process.Ext.effective_parent.entity_id
and process.entity_id
(they are unique and more appropriate)
❌ Author of the following commits did not sign a Contributor Agreement: cc150ef
Please, read and sign the above mentioned agreement if you want to contribute to this project
Thanks for the contribution @ar3diu - once you sign the CLA, @Samirbous can get this merged in 🎉
I already signed the contributor agreement, but I don't know why it's not updated...
Screenshot from the pdf downloaded:
@Mikaayenson should I close this one or...? I don't get why the CLA test did not pass since I signed the agreement. Any tips on investigating that?
The issue most likely is that your first commit cc150efbde95db42a21c5bebd0dc74cc177c2089
used a different name (
Andrei Rediu
vs ar3diu
. I bet if you sign with the former you should be g2g. If not lmk and we can push this in.
Hm, I noticed that too, but I don't get why the commit used that username. It probably has to do with my local instance of vs code. Anyway, I have signed the CLA now for both github (user)names.
Force merged this in since 2 approvals were checked and unit testing passed. Reviewed commit history and diff to ensure delta did not contain any anomalies.
Issues
https://github.com/elastic/detection-rules/issues/3803
Summary
Without a host grouping in the sequence of events, this rule triggers on events from different hosts which is not exactly the desired result.