Skip to content

[POC] Adds Entity ID Enricher integration#16409

Closed
opauloh wants to merge 1 commit intomainfrom
entity-store/euid-enricher
Closed

[POC] Adds Entity ID Enricher integration#16409
opauloh wants to merge 1 commit intomainfrom
entity-store/euid-enricher

Conversation

@opauloh
Copy link
Contributor

@opauloh opauloh commented Dec 8, 2025

Initializes the Entity ID Enricher integration, which enriches log data with stable user and host entity identifiers.

This integration introduces an ingest pipeline that automatically computes and adds user.entity.id and host.entity.id to logs-* data streams, improving entity analytics without requiring additional transforms.

The integration also includes documentation, sample events, and a manifest file to define the integration's metadata.

Proposed commit message

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Screenshots

Initializes the Entity ID Enricher integration, which enriches log data with stable user and host entity identifiers.

This integration introduces an ingest pipeline that automatically computes and adds `user.entity.id` and `host.entity.id` to `logs-*` data streams, improving entity analytics without requiring additional transforms.

The integration also includes documentation, sample events, and a manifest file to define the integration's metadata.
@opauloh opauloh added the Team:Cloud Security Cloud Security team [elastic/cloud-security-posture] label Dec 8, 2025
@elasticmachine
Copy link

elasticmachine commented Dec 8, 2025

💔 Build Failed

Failed CI Steps

History

@andrewkroh andrewkroh added New Integration Issue or pull request for creating a new integration package. documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. labels Dec 9, 2025
@botelastic
Copy link

botelastic bot commented Jan 8, 2026

Hi! We just realized that we haven't looked into this PR in a while. We're sorry! We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1. Thank you for your contribution!

@botelastic botelastic bot added the Stalled label Jan 8, 2026
@botelastic
Copy link

botelastic bot commented Feb 7, 2026

Hi! This PR has been stale for a while and we're going to close it as part of our cleanup procedure. We appreciate your contribution and would like to apologize if we have not been able to review it, due to the current heavy load of the team. Feel free to re-open this PR if you think it should stay open and is worth rebasing. Thank you for your contribution!

@botelastic botelastic bot closed this Feb 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. New Integration Issue or pull request for creating a new integration package. Stalled Team:Cloud Security Cloud Security team [elastic/cloud-security-posture]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants