Skip to content

[windows] FIx pipeline to set file hash for event 26#18501

Open
marc-gr wants to merge 1 commit intoelastic:mainfrom
marc-gr:fix/sysmon-e26-file-hash-not-process-hash
Open

[windows] FIx pipeline to set file hash for event 26#18501
marc-gr wants to merge 1 commit intoelastic:mainfrom
marc-gr:fix/sysmon-e26-file-hash-not-process-hash

Conversation

@marc-gr
Copy link
Copy Markdown
Contributor

@marc-gr marc-gr commented Apr 17, 2026

Proposed commit message

FIx pipeline to set file hash for event 26

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

@marc-gr marc-gr added Integration:windows Windows bugfix Pull request that fixes a bug issue Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform] labels Apr 17, 2026
@marc-gr marc-gr force-pushed the fix/sysmon-e26-file-hash-not-process-hash branch from 8ee47e0 to 9bd98d3 Compare April 17, 2026 13:06
@marc-gr marc-gr marked this pull request as ready for review April 17, 2026 13:07
@marc-gr marc-gr requested review from a team as code owners April 17, 2026 13:07
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)

changes:
- description: Map Sysmon event 26 file delete hashes to `file.hash` instead of `process.hash`.
type: bugfix
link: https://github.com/elastic/integrations/pull/18501
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High windows/changelog.yml:6

The changelog entry for version 3.8.2 uses https://github.com/elastic/integrations/pull/1 as the link, which is a placeholder PR number. Every other entry in this file references actual PR numbers (e.g., pull/18210, pull/17921). This will mislead anyone tracing the change to its originating PR. Consider updating to the correct PR number.

Suggested change
link: https://github.com/elastic/integrations/pull/18501
link: https://github.com/elastic/integrations/pull/1
🤖 Copy this AI Prompt to have your agent fix this:
In file packages/windows/changelog.yml around line 6:

The changelog entry for version `3.8.2` uses `https://github.com/elastic/integrations/pull/1` as the link, which is a placeholder PR number. Every other entry in this file references actual PR numbers (e.g., `pull/18210`, `pull/17921`). This will mislead anyone tracing the change to its originating PR. Consider updating to the correct PR number.

@elastic-vault-github-plugin-prod
Copy link
Copy Markdown

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link
Copy Markdown

💚 Build Succeeded

@pierrehilbert pierrehilbert added the Team:Elastic-Agent-Data-Plane Agent Data Plane team [elastic/elastic-agent-data-plane] label Apr 17, 2026
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue Integration:windows Windows Team:Elastic-Agent-Data-Plane Agent Data Plane team [elastic/elastic-agent-data-plane] Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants