Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

m365_defender: remove deprecated log data stream #13188

Conversation

chemamartinez
Copy link
Contributor

Proposed commit message

  • Logs data stream has been removed as Microsoft announced that, effective December 31st, 2024, three years after the original deprecation announcement, they reserve the right to turn off the SIEM API without further notice.
  • All references to this data stream have been removed, in tests, and docs.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

@chemamartinez chemamartinez added enhancement New feature or request breaking change Integration:m365_defender Microsoft M365 Defender Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Mar 20, 2025
@chemamartinez chemamartinez self-assigned this Mar 20, 2025
@chemamartinez chemamartinez force-pushed the m365_defender-remove-deprecated-data-stream branch from ee7c4d3 to 499220f Compare March 20, 2025 12:07
@elastic-vault-github-plugin-prod

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link

💚 Build Succeeded

History

cc @chemamartinez

@chemamartinez
Copy link
Contributor Author

/test stack 9.0.0-SNAPSHOT

@elasticmachine
Copy link

💚 Build Succeeded

cc @chemamartinez

@chemamartinez chemamartinez marked this pull request as ready for review March 20, 2025 17:27
@chemamartinez chemamartinez requested a review from a team as a code owner March 20, 2025 17:27
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@chemamartinez chemamartinez merged commit cd147fc into elastic:main Mar 24, 2025
8 checks passed
@chemamartinez chemamartinez deleted the m365_defender-remove-deprecated-data-stream branch March 24, 2025 08:04
@elastic-vault-github-plugin-prod

Package m365_defender - 3.0.0 containing this change is available at https://epr.elastic.co/package/m365_defender/3.0.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
breaking change enhancement New feature or request Integration:m365_defender Microsoft M365 Defender Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants