diff --git a/packages/m365_defender/changelog.yml b/packages/m365_defender/changelog.yml index addcb64ae84..108204c42ae 100644 --- a/packages/m365_defender/changelog.yml +++ b/packages/m365_defender/changelog.yml @@ -1,4 +1,9 @@ # newer versions go on top +- version: "2.14.3" + changes: + - description: Fix sslconnectioninspected event `network.protocol` getting set to `dns`. + type: bugfix + link: https://github.com/elastic/integrations/pull/10730 - version: "2.14.2" changes: - description: Fix `network.transport` and `network.protocol` processing. diff --git a/packages/m365_defender/data_stream/event/_dev/test/pipeline/test-device.log-expected.json b/packages/m365_defender/data_stream/event/_dev/test/pipeline/test-device.log-expected.json index 3732a6ba2f9..4a1b0016714 100644 --- a/packages/m365_defender/data_stream/event/_dev/test/pipeline/test-device.log-expected.json +++ b/packages/m365_defender/data_stream/event/_dev/test/pipeline/test-device.log-expected.json @@ -3128,7 +3128,7 @@ }, "network": { "direction": "outbound", - "protocol": "dns", + "protocol": "ssl", "transport": "tcp" }, "process": { diff --git a/packages/m365_defender/data_stream/event/elasticsearch/ingest_pipeline/pipeline_device.yml b/packages/m365_defender/data_stream/event/elasticsearch/ingest_pipeline/pipeline_device.yml index 2859db7a3cf..fe28885875e 100644 --- a/packages/m365_defender/data_stream/event/elasticsearch/ingest_pipeline/pipeline_device.yml +++ b/packages/m365_defender/data_stream/event/elasticsearch/ingest_pipeline/pipeline_device.yml @@ -2389,7 +2389,7 @@ processors: override: true - set: field: network.protocol - value: dns + value: ssl tag: set_network_protocol_ssl if: ctx.m365_defender?.event?.action?.type != null && ctx.m365_defender.event.action.type.toLowerCase().contains('ssl') override: true diff --git a/packages/m365_defender/manifest.yml b/packages/m365_defender/manifest.yml index 6105247491a..d5336220e2f 100644 --- a/packages/m365_defender/manifest.yml +++ b/packages/m365_defender/manifest.yml @@ -1,7 +1,7 @@ format_version: "3.0.2" name: m365_defender title: Microsoft M365 Defender -version: "2.14.2" +version: "2.14.3" description: Collect logs from Microsoft M365 Defender with Elastic Agent. categories: - "security"