Skip to content

rebundle for siem#123

Open
kcorbett-hdx wants to merge 34 commits into
mainfrom
LOTC-691-siem-bundle-v2
Open

rebundle for siem#123
kcorbett-hdx wants to merge 34 commits into
mainfrom
LOTC-691-siem-bundle-v2

Conversation

@kcorbett-hdx

@kcorbett-hdx kcorbett-hdx commented Mar 17, 2026

Copy link
Copy Markdown
Collaborator

rebundle for siem

@kcorbett-hdx kcorbett-hdx added skip-bundle-ci Skips all CI workflows skip-bundle-format Skips bundle formatting; validates bundles labels Mar 17, 2026
@kcorbett-hdx kcorbett-hdx temporarily deployed to bundle-validator-env March 17, 2026 16:13 — with GitHub Actions Inactive
@kcorbett-hdx kcorbett-hdx removed the skip-bundle-format Skips bundle formatting; validates bundles label Mar 17, 2026
@kcorbett-hdx kcorbett-hdx temporarily deployed to bundle-validator-env March 17, 2026 16:47 — with GitHub Actions Inactive
@kcorbett-hdx kcorbett-hdx temporarily deployed to bundle-validator-env March 17, 2026 16:56 — with GitHub Actions Inactive
@kcorbett-hdx kcorbett-hdx removed the skip-bundle-ci Skips all CI workflows label Mar 17, 2026
@kcorbett-hdx kcorbett-hdx added the skip-bundle-format Skips bundle formatting; validates bundles label Mar 17, 2026
@kcorbett-hdx kcorbett-hdx temporarily deployed to bundle-validator-env March 17, 2026 18:45 — with GitHub Actions Inactive
@kcorbett-hdx kcorbett-hdx temporarily deployed to bundle-validator-env March 17, 2026 18:45 — with GitHub Actions Inactive
@kcorbett-hdx kcorbett-hdx removed the skip-bundle-format Skips bundle formatting; validates bundles label Mar 17, 2026
@kcorbett-hdx kcorbett-hdx changed the title Lotc 691 siem bundle v2 rebundle for siem Mar 17, 2026
@kcorbett-hdx kcorbett-hdx mentioned this pull request Mar 18, 2026
@kcorbett-hdx kcorbett-hdx added the skip-bundle-format Skips bundle formatting; validates bundles label Mar 23, 2026
@kcorbett-hdx kcorbett-hdx temporarily deployed to bundle-validator-env March 23, 2026 22:52 — with GitHub Actions Inactive
The siem transform uses timestamp as the primary column, not reqTimeSec.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@hdx-leonardo hdx-leonardo temporarily deployed to bundle-validator-env April 6, 2026 12:47 — with GitHub Actions Inactive
@hdx-leonardo hdx-leonardo temporarily deployed to bundle-validator-env April 6, 2026 12:47 — with GitHub Actions Inactive
kevinborkman-hub and others added 2 commits April 7, 2026 14:47
Move all contents from trafficpeak/siem/0.9.0/ up to trafficpeak/siem/
and update base_url to match. Aligns with LOTC-1348 flat directory structure.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@kevinborkman-hub kevinborkman-hub temporarily deployed to bundle-validator-env April 7, 2026 18:48 — with GitHub Actions Inactive
@kevinborkman-hub kevinborkman-hub temporarily deployed to bundle-validator-env April 7, 2026 18:48 — with GitHub Actions Inactive
kevinborkman-hub and others added 2 commits April 15, 2026 15:54
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@kevinborkman-hub kevinborkman-hub temporarily deployed to bundle-validator-env April 15, 2026 19:57 — with GitHub Actions Inactive
github-actions Bot and others added 2 commits April 15, 2026 19:58
… rebundle for CI

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@kevinborkman-hub kevinborkman-hub temporarily deployed to bundle-validator-env April 15, 2026 20:31 — with GitHub Actions Inactive
@kcorbett-hdx kcorbett-hdx removed the skip-bundle-format Skips bundle formatting; validates bundles label Apr 15, 2026
kevinborkman-hub and others added 5 commits April 28, 2026 15:01
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…data

Auto-shifter doesn't handle nested JSON pointers (httpMessage/start);
patched .originals embedded sample_data.httpMessage.start from
1491303422 (2017-04-04) to 1775001600 (2026-04-01) so the freshness
validator passes. Pipeline limitation tracked separately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants