elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
30 stars 447 forks source link

Update bbot integration to support recent major v2.x release #11741

Open colin-stubbs opened 1 week ago

colin-stubbs commented 1 week ago

Purpose

BBOT v2.x has now been available for a number of months and is in production use by many users.

Significant JSON structure and field changes have occurred in the BBOT output modules that necessitates an Elastic integration update.

An update is required that guarantees backwards compatibility with existing BBOX v1.x data as well as new BBOT v2.x data such that it is searchable and not documents are excluded from search results.

HTTP webhook (filebeat http_endpoint) style inputs should be added to the integration to complement the BBOT http output module.

All changes

Log dataset changes