Skip to content

[b/517348034] Migrating 5 new log_types from piper workspace to GitHub#877

Open
sontih-debug wants to merge 5 commits into
mainfrom
migrating-logtypes_into_git
Open

[b/517348034] Migrating 5 new log_types from piper workspace to GitHub#877
sontih-debug wants to merge 5 commits into
mainfrom
migrating-logtypes_into_git

Conversation

@sontih-debug
Copy link
Copy Markdown
Contributor

@sontih-debug sontih-debug commented May 28, 2026

Description

The purpose of this migration is to establish a community Git repository that enables customer-driven parser updates. Customers will be able to pull the codebase, make modifications, and submit their changes for review and approval by the CBN team.

Log_types:

1.TRENDMICRO_VISION_ONE_CONTAINER_VULNERABILITIES
2.THREATLOCKER
3.TERADATA_DB
4.SOPHOS_DHCP
5.SYMANTEC_SA


Checklist:

Please ensure you have completed the following items before submitting your PR.
This helps us review your contribution faster and more efficiently.

General Checks:

  • I have read and followed the project's contributing.md guide.
  • My code follows the project's coding style guidelines.
  • I have performed a self-review of my own code.
  • My changes do not introduce any new warnings.
  • My changes pass all existing tests.
  • I have added new tests where appropriate to cover my changes. (If applicable)
  • I have updated the documentation where necessary (e.g., README, API docs). (If applicable)

Open-Source Specific Checks:

  • My changes do not introduce any Personally Identifiable Information (PII) or sensitive customer data.
  • My changes do not expose any internal-only code examples, configurations, or URLs.
  • All code examples, comments, and messages are generic and suitable for a public repository.
  • I understand that any internal context or sensitive details related to this work are handled separately in internal systems (Buganizer for Google team members).

For Google Team Members and Reviewers Only:

  • I have included the Buganizer ID in the PR title or description (e.g., "Internal Buganizer ID: 123456789" or "Related Buganizer: go/buganizer/123456789").
  • I have ensured that all internal discussions and PII related to this work remain in Buganizer.
  • I have tagged the PR with one or more labels that reflect the pull request purpose.

Screenshots (If Applicable)

If your changes involve UI or visual elements, please include screenshots or GIFs here.
Ensure any sensitive data is redacted or generalized.


Further Comments / Questions

Any additional comments, questions, or areas where you'd like specific feedback.
TAG SKIP_GOOGLE_PARSER_CHECK="Not Applicable for now"

@sontih-debug sontih-debug requested a review from a team as a code owner May 28, 2026 04:43
@gemini-code-assist
Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request expands the repository's log parsing capabilities by introducing support for several third-party security and database products. Each new parser includes the necessary configuration, metadata, and test datasets to ensure accurate data normalization and integration.

Highlights

  • New Log Parsers: Added support for five new log types: SOPHOS DHCP, Symantec Security Analytics, Teradata DB, ThreatLocker, and Trend Micro Vision One Container Vulnerabilities.
  • Test Coverage: Included metadata, raw log samples, and expected UDM events for each new parser to ensure robust validation and ingestion.
New Features

🧠 You can now enable Memory (public preview) to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@sontih-debug sontih-debug changed the title Migrating logtypes into git Migrating 5 new log_types from piper workspace to GitHub May 28, 2026
Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces Logstash/CBN configurations, metadata, and test data for several new log sources, including SOPHOS_DHCP, SYMANTEC_SA, TERADATA_DB, THREATLOCKER, and TRENDMICRO_VISION_ONE_CONTAINER_VULNERABILITIES. The reviewer identified several critical syntax and logical issues across these configurations that must be addressed before merging. Specifically, the use of unsupported native for loops in the SOPHOS_DHCP parser and the invalid on_error option inside mutate blocks in the SYMANTEC_SA and TERADATA_DB parsers will cause compilation errors. Additionally, initializing map fields to empty strings in the SYMANTEC_SA and TRENDMICRO parsers breaks nested UDM path assignments, while the THREATLOCKER parser contains an incorrect string-to-array comparison and an existence check on a boolean field that should be updated to an explicit equality check.

@sontih-debug sontih-debug changed the title Migrating 5 new log_types from piper workspace to GitHub [b/517348034] Migrating 5 new log_types from piper workspace to GitHub May 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants