-
Notifications
You must be signed in to change notification settings - Fork 502
[Netskope] Add alerts_events_v2 data stream to fetch the data for alerts_v2 and events_v2 from a single queue #15697
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
[Netskope] Add alerts_events_v2 data stream to fetch the data for alerts_v2 and events_v2 from a single queue #15697
Conversation
…ents_v2 data from a single queue
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
| bucket_arn: {{bucket_arn}} | ||
| {{/if}} | ||
| {{#if number_of_workers}} | ||
| number_of_workers: {{number_of_workers}} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hello @moxarth-rathod
This needs to be outside #if collect_s3_logs and #if queue_url as the setting number_of_workers is applied to both ways of getting data from S3, polling and SQS, the setting max_number_of_messages is ignored on agents higher than 8.16+
For more context this was reported on #13179 and fixed on multiple integrations on #13350
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks! I've made the changes accordingly.
|
|
||
| **Note**: It is recommended to use the combined alerts_events_v2 data stream rather than configuring the individual events_v2 or alerts_v2 data stream. The alerts_events_v2 stream automatically directs logs to the appropriate individual data streams. | ||
|
|
||
| If the individual v2 data streams, events_v2 or alerts_v2, are used via SQS, it is necessary to implement event-based bucket segregation. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This may change in the future, but according to current Netskope documentation, if you choose any event type and alerts, they will be streamed together.
The user may choose to stream only events or to stream only alerts, but when choosing alerts and any other event type, they will be streamed together.
💔 Build Failed
Failed CI StepsHistory
|
Proposed commit message
Checklist
changelog.ymlfile.How to test this PR locally
Additionally, the following cloud credentials are required to setup:
AWS:
Related issues