Skip to content

[cisco_ise] Add ECS category/type/outcome for Administrative and Operational Audit events - #21638

Merged
Niceplace merged 11 commits into
mainfrom
cisco_ise-admin-audit-ecs
Sep 29, 2026
Merged

Niceplace merged 11 commits into
mainfrom
cisco_ise-admin-audit-ecs

Conversation

@Niceplace

@Niceplace Niceplace commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The `pipeline_administrative_and_operational_audit` pipeline was missing `event.category`, `event.type`, and `event.outcome` for several message codes, even though the raw events contained sufficient information to derive them.

Administrator login events

Code Meaning category type outcome
51000 GUI admin login failed iam, authentication admin, info failure
51008 Account locked after failed attempts iam, authentication admin, info failure
51023 Account unlocked iam admin, change, info success
51025 / 51106 ERS API authentication failed iam, authentication user, info failure

51025 (ISE 3.0+) and 51106 (pre-3.0, deleted in ISE 3.0) are the same event — Cisco replaced 51106 with 51025 in Release 3.0. Both carry identical message text and `AdminInterface=ERS`. Per ECS, `event.type:admin` covers administrative changes within an IAM framework that do not specifically affect a user or group; a failed ERS API authentication is not an administrative change. `event.type:user` is used instead, consistent with the ECS definition and the rest of the password-change class.

Password-change events — mapped by code; no message-text regex needed

Code(s) Meaning category type outcome
51100 Password changed successfully iam user, change, info success
51101-51105, 51107, 51115, 51116 New password rejected iam user, change, info failure

Configuration-change events (52000/52001/52002 already had category and type)

  • 52001 with `FailureFlag=true` sets `event.outcome: failure`
  • All others (`FailureFlag=false`, no flag, 52000, 52002) set `event.outcome: success`

Cisco syslog reference has no dedicated configuration-change failure code (52003-52022 are distributed-management codes), so success is inferred from the event being emitted. `FailureFlag` semantics are not formally documented by Cisco and are inferred from observed samples.

Both the append processors and the Painless script reference tables are updated identically. Anonymized fixture lines and regenerated expected JSON cover every new code path.

Checklist

  • My code follows the style guidelines of this project.
  • I have added tests that prove my fix is effective.
  • My changes pass the pipeline test suite.
  • My PR includes a changelog entry.

… events

Fixes missing event.category, event.type, and event.outcome fields for
several Administrative & Operational Audit message codes.

Administrator login events:
- 51000: adds iam+authentication / admin+info (outcome already failure)
- 51008 (account locked after failed attempts): iam+authentication / admin+info / failure
- 51023 (account unlocked): iam / admin+change+info / success
- 51025 / 51106 (API/ERS auth failed): iam+authentication / admin+info / failure

Password-change events (mapped by code, no regex needed):
- 51100 (success): iam / user+change+info / success
- 51101-51105, 51107, 51115, 51116 (rejected new password): iam / user+change+info / failure

Configuration-change events (52000/52001/52002):
- Already had category+type; now also expose event.outcome.
- 52001 with FailureFlag=true → failure.
- 52000/52001 (no flag)/52002 → success. Cisco does not document a
  separate failure code for configuration changes; FailureFlag semantics
  are inferred from observed samples only.

Both the append processors and the Painless script reference tables are
updated identically; ten anonymized fixture lines and their expected JSON
are added to cover every new branch.
@Niceplace Niceplace added the bug Something isn't working, use only for issues label Sep 24, 2026
@Niceplace
Niceplace requested a review from a team as a code owner September 24, 2026 15:17
@Niceplace Niceplace added Integration:cisco_ise Cisco ISE Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience] labels Sep 24, 2026
Copilot AI lite review requested due to automatic review settings September 24, 2026 15:17
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/integration-experience (Team:Integration-Experience)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Correct the 51106 mapping and cover the remaining advertised event codes.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Adds ECS category, type, and outcome mappings for Cisco ISE administrative and operational audit events.

Changes:

  • Extends administrator, password, and configuration-event mappings.
  • Adds fixtures and expected pipeline outputs.
  • Bumps the package version and adds a changelog entry.
File Summary
packages/​cisco_ise/​manifest.yml Bumps version to 1.33.1.
packages/​cisco_ise/​data_stream/​log/​elasticsearch/​ingest_pipeline/​pipeline_administrative_and_operational_audit.yml Adds ECS mappings and configuration outcomes. Moderate issue: 51106 is incorrectly mapped as a password-change event; test coverage also omits several advertised codes.
packages/​cisco_ise/​data_stream/​log/​_dev/​test/​pipeline/​test-pipeline-administrative-and-operational-audit.log-expected.json Updates expected parsed results.
packages/​cisco_ise/​data_stream/​log/​_dev/​test/​pipeline/​test-pipeline-administrative-and-operational-audit.log Adds audit-event fixtures.
packages/​cisco_ise/​changelog.yml Documents the bug fix.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

Comment thread packages/cisco_ise/changelog.yml Outdated
…re coverage

- 51106 is in Cisco class "User change password" (confirmed in Cisco ISE
  syslog reference), not Administrator-Login. Correct its ECS mapping:
  remove from authentication category and admin type; add to user type.
  Result: iam / user+change+info / failure (consistent with 51101-51116).
- Add individual fixture lines for 51102, 51103, 51104, 51105, 51107,
  and 51116 so that every code listed in the pipeline conditions has its
  own test assertion.
Copilot AI review requested due to automatic review settings September 24, 2026 17:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The remaining finding is a non-blocking documentation nit.

Review effort: Lite
Findings: 1 Low severity

Open (1)
Resolved since last review (1)

Copilot AI review requested due to automatic review settings September 24, 2026 17:19
@github-actions

Copy link
Copy Markdown
Contributor

TL;DR

The Vale Lint workflow run failed before linting started: job setup could not stage a file from elastic/docs-actions@v1 (retry.js missing). Immediate action is to re-run once (in case of transient staging) and, if it reproduces, pin/update the docs action to a known-good ref.

Remediation

  • Re-run the failed check once to rule out transient action-download/staging corruption.
  • If it fails again with the same missing-file path, update the workflow reference for elastic/docs-actions to a known-good commit/tag (or coordinate with docs-actions maintainers), then re-run Vale.
  • Confirm the rerun gets past Set up job and into actual lint execution.
Investigation details

Root Cause

The only failing job was Lint user-facing content, and it failed in Set up job while preparing required actions. The runner downloaded elastic/docs-actions@v1 and then errored because a required script file was not present in the staged action contents.

Evidence

Download action repository 'elastic/docs-actions@v1' (SHA:fc755926be762df2dee7783b78c464768c4a571e)
##[error]Could not find file '/home/runner/work/_actions/_temp_.../docs-actions-fc755926be762df2dee7783b78c464768c4a571e/docs-builder/preview/cleanup/scripts/retry.js'.

Validation

  • Not run locally (workflow/environment setup failure; no package code path executed).

Follow-up

  • If this is reproducible across PRs, treat as shared CI action regression rather than PR-content-specific failure.

What is this? | From workflow: PR Actions Detective

Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: 1 Low severity

Open (1)

@github-actions github-actions Bot mentioned this pull request Sep 24, 2026
Copilot AI review requested due to automatic review settings September 25, 2026 15:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Only a minor documentation nit remains; no blocking issues were identified.

Review effort: Lite
Findings: 1 Low severity

Open (1)

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

Code 51106 is an ERS API authentication failure in the "User change
password" class. A prior draft incorrectly included it in the admin
event.type; the correct mapping is user+info (same as other auth-failure
codes in that class). No outcome or category change needed.

Fixes: #21584
Copilot AI review requested due to automatic review settings September 25, 2026 18:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Remove 51106 from the authentication category and update the corresponding reference table and fixture output.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)

@qcorporation qcorporation added the bugfix Pull request that fixes a bug issue label Sep 26, 2026
Copilot AI review requested due to automatic review settings September 28, 2026 14:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review comments remain, and all reviewers assessed it as ready.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)

51025 (ISE 3.0+) is the successor to the deleted 51106 (pre-3.0) —
both are ERS API authentication failures in the "User change password"
class. They should have identical ECS mappings.

Per ECS, event.type:admin covers "administrative changes within an IAM
framework that do not specifically affect a user or group" (e.g. adding
an application to a federation). A failed ERS API authentication is not
an administrative change; it affects a user context and nothing is
modified. Removing admin and aligning 51025 with user+info, consistent
with 51106 and with the ECS definition.
Copilot AI review requested due to automatic review settings September 29, 2026 15:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Correct code 51025 classification from user to admin in both mapping implementations.

Review effort: Lite
Findings: 2 Medium severity · 1 Low severity

Open (3)

Copilot AI review requested due to automatic review settings September 29, 2026 15:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)
Resolved since last review (1)

Copilot AI review requested due to automatic review settings September 29, 2026 16:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The requested mappings, fixtures, version update, and changelog changes are complete.

Review effort: Lite
Findings: None

Resolved since last review (2)

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@vera-review-bot

Copy link
Copy Markdown

🟢 Reviewed the latest commits add755d — nothing new beyond already posted comments.

Review summary

Issues found across earlier commits bf09bfc — 1 low
  • 🔵 Code 51106 is still in the authentication category list although the maintainer's follow-up comment says it was removed to match its Cisco 'User change password' class (link)
Issues found across earlier commits a4487e9 — 1 medium, 2 low
  • 🟡 Code 51106 (ERS/API authentication failed) is tagged event.type change although it is an authentication failure and the PR description maps it to admin, info only (link) (Outdated)
  • 🔵 Changelog link points at an issue URL (link) (Outdated)

Package-level:

  • 🔵 Proposed commit message

    cisco_ise: add ECS category, type and outcome for administrative audit events
    
    The pipeline_administrative_and_operational_audit pipeline did not set
    event.category, event.type, or event.outcome for several Administrative
    and Operational Audit message codes even though the events carry enough
    information to derive them.
    
    Administrator login codes 51000, 51008, 51023, 51025 and 51106 now get
    iam/authentication categories, admin type and a success or failure
    outcome. Password-change codes 51100, 51101-51105, 51107, 51115 and
    51116 get iam category, user/change type and an outcome based on the
    code. Configuration-change codes 52000, 52001 and 52002 now expose
    event.outcome: 52001 records with FailureFlag=true are marked failure,
    all other configuration-change records are marked success.
    
    The append processors and the Painless reference tables are updated
    identically, and anonymized fixture lines cover the new code paths.
    
    Fixes #​21584
    

A new commit triggers another review — at most once every 15 minutes. I skip the PR while it's approved or has merge conflicts.

🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills

⚠️ Automated review — verify suggestions before applying.

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

History

@mergify

mergify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again.

@Niceplace
Niceplace merged commit 6a0e546 into main Sep 29, 2026
15 checks passed
@Niceplace
Niceplace deleted the cisco_ise-admin-audit-ecs branch September 29, 2026 18:02
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package cisco_ise - 1.33.1 containing this change is available at https://epr.elastic.co/package/cisco_ise/1.33.1/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working, use only for issues bugfix Pull request that fixes a bug issue Integration:cisco_ise Cisco ISE Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants