-
Notifications
You must be signed in to change notification settings - Fork 444
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[cisco asa] grok processor warnings shown to user after installing assets #9489
Comments
Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices) |
So after investigating this one, I can see why regex engine on Elasticsearch side is throwing the respective warnings so a basic regex example regex
so essentially the regex engine is saying to us hey I will replace the combo of about the hyphen warning this is not escaped inside the [...] so again it makes total sense Preparing a fix to mitigate the warnings |
Package cisco_asa - 2.32.1 containing this change is available at https://epr.elastic.co/search?package=cisco_asa |
Users installing the cisco asa integration assets will see a ton of warnings from the grok processors of the ingest pipeline like these:
Seems related to elastic/beats#36326, and overall lack of escaping of certain characters and non-optimal design of the regexes.
The text was updated successfully, but these errors were encountered: