Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[AUTO] Incremented version to 2.16.1. #1221

Open
wants to merge 70 commits into
base: 2.16
Choose a base branch
from

Conversation

opensearch-trigger-bot[bot]
Copy link
Contributor

I've noticed that a new tag 2.16.0.0 was pushed, and incremented the version from 2.16.0 to 2.16.1.

opensearch-trigger-bot bot and others added 13 commits February 19, 2025 12:42
(cherry picked from commit 362f0d6)

Signed-off-by: Riya Saxena <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
…1039)

Signed-off-by: Subhobrata Dey <[email protected]>
(cherry picked from commit 20905ce)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
(cherry picked from commit 65c1519)

Signed-off-by: Riya Saxena <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
* added correlationAlert integ tests

Signed-off-by: Riya Saxena <[email protected]>

* added licences

Signed-off-by: Riya Saxena <[email protected]>

* fixed imports

Signed-off-by: Riya Saxena <[email protected]>

* deleted SecureCorrelationAlerts Tests, will add later

Signed-off-by: Riya Saxena <[email protected]>

---------

Signed-off-by: Riya Saxena <[email protected]>
(cherry picked from commit e8d7879)
Signed-off-by: AWSHurneyt <[email protected]>
(cherry picked from commit 29cb35b)

Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
(cherry picked from commit d51b5a4)

Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Joanne Wang <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
* Threat Intel Analytics (#1098)

Threat Intel Analytics Added

---------

Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: Chase Engelbrecht <[email protected]>
Signed-off-by: Riya <[email protected]>
Signed-off-by: Riya Saxena <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>
Co-authored-by: AWSHurneyt <[email protected]>
Co-authored-by: Subhobrata Dey <[email protected]>
Co-authored-by: Chase <[email protected]>
Co-authored-by: Riya <[email protected]>

* fix compile

Signed-off-by: Joanne Wang <[email protected]>

* update sa commons jar

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: Chase Engelbrecht <[email protected]>
Signed-off-by: Riya <[email protected]>
Signed-off-by: Riya Saxena <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>
Co-authored-by: AWSHurneyt <[email protected]>
Co-authored-by: Subhobrata Dey <[email protected]>
Co-authored-by: Chase <[email protected]>
Co-authored-by: Riya <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
…m S3 downloaded iocs file (#1129) (#1148)

(cherry picked from commit 5d3dbca)

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
…g apis. null check for alias (#1131) (#1153)

(cherry picked from commit 23ab84a)

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
* Changes threat intel default store config model (#1133)

* change store config model

Signed-off-by: Joanne Wang <[email protected]>

* add validation to ioc type enum name

Signed-off-by: Joanne Wang <[email protected]>

* change alias to index pattern

Signed-off-by: Joanne Wang <[email protected]>

* make variables final

Signed-off-by: Joanne Wang <[email protected]>

* ensure ioc types are part of ioc_types

Signed-off-by: Joanne Wang <[email protected]>

* fix integ test

Signed-off-by: Joanne Wang <[email protected]>

* remove alias and rename active index

Signed-off-by: Joanne Wang <[email protected]>

* fix test

Signed-off-by: Joanne Wang <[email protected]>

* add enabled for scan flag in source config.

Signed-off-by: Surya Sashank Nistala <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
Co-authored-by: Surya Sashank Nistala <[email protected]>
(cherry picked from commit 3be4828)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* fix imports

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Surya Sashank Nistala <[email protected]>
Co-authored-by: Joanne Wang <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
opensearch-trigger-bot bot and others added 29 commits February 19, 2025 12:43
(cherry picked from commit ffcc807)

Signed-off-by: Dennis Toepker <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Dennis Toepker <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
…/upload-artifac2 to @V3 (#1303) (#1318)

Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
* handle exception arising from trying to search with sort on empty index



* add setting to test max term count in threat intel ioc scan terms query and verify grouped listener wiring



* remove unused variable



* avoid grouped listener being initiated with size 0



* add verification that empty index scan is handled gracefully



---------


(cherry picked from commit 39c29d4)

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
* Add null check while adding fetched iocs into per-indicator-type map (#1335)

* add null check while adding fetched iocs into per-indicator-type map

Signed-off-by: Surya Sashank Nistala <[email protected]>

* adds tests verifying monitor configured on multiple indicator types

Signed-off-by: Surya Sashank Nistala <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>

* fix constructor for 2.x

Signed-off-by: Surya Sashank Nistala <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
…mary shards for system indices to 1 (#1358) (#1359)

Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
#1361)

* Fix notifications listener leak in threat intel monitor (#1356)

* notifications listener leak

Signed-off-by: Surya Sashank Nistala <[email protected]>

* change error handling to succeed monitor execution when alerts or notifications fail

Signed-off-by: Surya Sashank Nistala <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
(cherry picked from commit 98edd70)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* fix stringentity constructor issue

Signed-off-by: Subhobrata Dey <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: Subhobrata Dey <[email protected]>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Subhobrata Dey <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
(cherry picked from commit ffcaf43)

Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
(cherry picked from commit b185440)

Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
(cherry picked from commit 6f543b5)

Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
* Fixed finding number returned by ListIOCs API capping at 10,000.



* Added integ test for fix.



* Removed extraneous query params.



* Added additional test case.



---------


(cherry picked from commit d5c8f7a)

Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
…) (#1384)

(cherry picked from commit 3d1fcd5)

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
* Added check to prevent resource_already_exists_exception when indexing more than 10k iocs.



* Changed log message.



---------


(cherry picked from commit 4432b36)

Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
* Added 2.18.0 release notes.



* Added 2.18.0 release notes.



---------


(cherry picked from commit 9693501)

Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
* add validation for source config and allow null to be read in parser



* add parsing tests



* add additional validation



---------


(cherry picked from commit 364f42d)

Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
…1418) (#1433)

* optimize sigma aggregation rule based detectors execution workflow

Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
…rules (#1423) (#1428)

(cherry picked from commit 8a4176b)

Signed-off-by: Surya Sashank Nistala <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
… (#1434)

* De-dupe Alerts generated by Aggregation Sigma Rules fix



* De-dupe Alerts generated by Aggregation Sigma Rules fix



* De-dupe Alerts generated by Aggregation Sigma Rules fix



* tests fix



* tests fix



---------


(cherry picked from commit 4845337)

Signed-off-by: Riya Saxena <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
* bumping version to 2.19.0

Signed-off-by: Dennis Toepker <[email protected]>

* Update ci.yml

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: Dennis Toepker <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
Co-authored-by: Dennis Toepker <[email protected]>
Co-authored-by: AWSHurneyt <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
…1443)

* Adding various OCSF 1.1 fields to log type static mappings



* fixing IT failures



* removed vestigial exception throw



* turning all ocsf 1.0 replacements with additions



* fixed ITs



---------



(cherry picked from commit 189b9e5)

Signed-off-by: Dennis Toepker <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Dennis Toepker <[email protected]>
Co-authored-by: AWSHurneyt <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
* OCSF1.1 Fixes



* reverting var declare ordering



* adding brief comment explaining importance of the OCSF check ordering



---------



(cherry picked from commit 3e6320b)

Signed-off-by: Dennis Toepker <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Dennis Toepker <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
(cherry picked from commit dca74ce)

Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: AWSHurneyt <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
* Fix CVE-2024-47535.

Signed-off-by: AWSHurneyt <[email protected]>

* Bumped upload-artifact action version.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
(cherry picked from commit d4f44ec)

Co-authored-by: AWSHurneyt <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
* Refactored flaky test.

Signed-off-by: AWSHurneyt <[email protected]>

* Refactored test for flakiness.

Signed-off-by: AWSHurneyt <[email protected]>

* Updated tests.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
(cherry picked from commit 783167a)

Co-authored-by: AWSHurneyt <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
* Added 2.19 release notes.



* Added 2.19 release notes.



---------


(cherry picked from commit 3b6ed5f)

Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: GitHub <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
@AWSHurneyt AWSHurneyt force-pushed the create-pull-request/patch branch from 8f5d2a4 to c8b77ae Compare February 19, 2025 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

7 participants