Repository navigation
[cisco_ise] Add ECS category/type/outcome for Administrative and Operational Audit events - #21638
Conversation
… events Fixes missing event.category, event.type, and event.outcome fields for several Administrative & Operational Audit message codes. Administrator login events: - 51000: adds iam+authentication / admin+info (outcome already failure) - 51008 (account locked after failed attempts): iam+authentication / admin+info / failure - 51023 (account unlocked): iam / admin+change+info / success - 51025 / 51106 (API/ERS auth failed): iam+authentication / admin+info / failure Password-change events (mapped by code, no regex needed): - 51100 (success): iam / user+change+info / success - 51101-51105, 51107, 51115, 51116 (rejected new password): iam / user+change+info / failure Configuration-change events (52000/52001/52002): - Already had category+type; now also expose event.outcome. - 52001 with FailureFlag=true → failure. - 52000/52001 (no flag)/52002 → success. Cisco does not document a separate failure code for configuration changes; FailureFlag semantics are inferred from observed samples only. Both the append processors and the Painless script reference tables are updated identically; ten anonymized fixture lines and their expected JSON are added to cover every new branch.
|
Pinging @elastic/integration-experience (Team:Integration-Experience) |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Correct the 51106 mapping and cover the remaining advertised event codes.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
Adds ECS category, type, and outcome mappings for Cisco ISE administrative and operational audit events.
Changes:
- Extends administrator, password, and configuration-event mappings.
- Adds fixtures and expected pipeline outputs.
- Bumps the package version and adds a changelog entry.
| File | Summary |
|---|---|
packages/cisco_ise/manifest.yml |
Bumps version to 1.33.1. |
packages/cisco_ise/data_stream/log/elasticsearch/ingest_pipeline/pipeline_administrative_and_operational_audit.yml |
Adds ECS mappings and configuration outcomes. Moderate issue: 51106 is incorrectly mapped as a password-change event; test coverage also omits several advertised codes. |
packages/cisco_ise/data_stream/log/_dev/test/pipeline/test-pipeline-administrative-and-operational-audit.log-expected.json |
Updates expected parsed results. |
packages/cisco_ise/data_stream/log/_dev/test/pipeline/test-pipeline-administrative-and-operational-audit.log |
Adds audit-event fixtures. |
packages/cisco_ise/changelog.yml |
Documents the bug fix. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
…re coverage - 51106 is in Cisco class "User change password" (confirmed in Cisco ISE syslog reference), not Administrator-Login. Correct its ECS mapping: remove from authentication category and admin type; add to user type. Result: iam / user+change+info / failure (consistent with 51101-51116). - Add individual fixture lines for 51102, 51103, 51104, 51105, 51107, and 51116 so that every code listed in the pipeline conditions has its own test assertion.
TL;DRThe Vale Lint workflow run failed before linting started: job setup could not stage a file from Remediation
Investigation detailsRoot CauseThe only failing job was Lint user-facing content, and it failed in Set up job while preparing required actions. The runner downloaded Evidence
Validation
Follow-up
What is this? | From workflow: PR Actions Detective Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not. |
🚀 Benchmarks reportTo see the full report comment with |
Code 51106 is an ERS API authentication failure in the "User change password" class. A prior draft incorrectly included it in the admin event.type; the correct mapping is user+info (same as other auth-failure codes in that class). No outcome or category change needed. Fixes: #21584
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Remove 51106 from the authentication category and update the corresponding reference table and fixture output.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
51025 (ISE 3.0+) is the successor to the deleted 51106 (pre-3.0) — both are ERS API authentication failures in the "User change password" class. They should have identical ECS mappings. Per ECS, event.type:admin covers "administrative changes within an IAM framework that do not specifically affect a user or group" (e.g. adding an application to a federation). A failed ERS API authentication is not an administrative change; it affects a user context and nothing is modified. Removing admin and aligning 51025 with user+info, consistent with 51106 and with the ECS definition.
|
✅ All changelog entries have the correct PR link. |
|
🟢 Reviewed the latest commits add755d — nothing new beyond already posted comments. Review summaryIssues found across earlier commits bf09bfc — 1 low
Issues found across earlier commits a4487e9 — 1 medium, 2 low
Package-level:
🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills
|
💚 Build Succeeded
History
|
|
This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again. |
|
Package cisco_ise - 1.33.1 containing this change is available at https://epr.elastic.co/package/cisco_ise/1.33.1/ |


Summary
The `pipeline_administrative_and_operational_audit` pipeline was missing `event.category`, `event.type`, and `event.outcome` for several message codes, even though the raw events contained sufficient information to derive them.
Administrator login events
51025 (ISE 3.0+) and 51106 (pre-3.0, deleted in ISE 3.0) are the same event — Cisco replaced 51106 with 51025 in Release 3.0. Both carry identical message text and `AdminInterface=ERS`. Per ECS, `event.type:admin` covers administrative changes within an IAM framework that do not specifically affect a user or group; a failed ERS API authentication is not an administrative change. `event.type:user` is used instead, consistent with the ECS definition and the rest of the password-change class.
Password-change events — mapped by code; no message-text regex needed
Configuration-change events (52000/52001/52002 already had category and type)
Cisco syslog reference has no dedicated configuration-change failure code (52003-52022 are distributed-management codes), so success is inferred from the event being emitted. `FailureFlag` semantics are not formally documented by Cisco and are inferred from observed samples.
Both the append processors and the Painless script reference tables are updated identically. Anonymized fixture lines and regenerated expected JSON cover every new code path.
Checklist