Skip to content

Conversation

@chrisberkhout
Copy link
Contributor

@chrisberkhout chrisberkhout commented Nov 26, 2025

Proposed commit message

[trend_micro_vision_one] No error for unparsable `...detection.request` URI

The `trend_micro_vision_one.detection.request` field sometimes has
values with typos in them, which makes the `uri_parts` processor fail.

An error in `error.message` is confusing. That is removed. The original
value will remain in `trend_micro_vision_one.detection.request` and
`url.*` will be populated if the `uri_parts` processor is successful.

An error is kept for the other `uri_parts` processor usage, for
`trend_micro_vision_one.alert.workbench_link`, since that seems to not
be entered by a user and therefore should always be a correct URL.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

@chrisberkhout chrisberkhout self-assigned this Nov 26, 2025
@chrisberkhout chrisberkhout requested a review from a team as a code owner November 26, 2025 09:33
@chrisberkhout chrisberkhout added enhancement New feature or request Integration:trend_micro_vision_one Trend Micro Vision One Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Nov 26, 2025
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link

💚 Build Succeeded

cc @chrisberkhout

Copy link
Contributor

@kcreddy kcreddy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Curious what was the error.message like in such case.

@chrisberkhout
Copy link
Contributor Author

@kcreddy The message was like this: unable to parse URI [https://pt-br.facebook .com/someuser/]

@chrisberkhout chrisberkhout merged commit 910e854 into elastic:main Dec 2, 2025
7 checks passed
@elastic-vault-github-plugin-prod

Package trend_micro_vision_one - 2.5.0 containing this change is available at https://epr.elastic.co/package/trend_micro_vision_one/2.5.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:trend_micro_vision_one Trend Micro Vision One Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants