Skip to content

Conversation

@mohitjha-elastic
Copy link
Contributor

Backport

This will backport the following commits from main to 9.1:

Questions ?

Please refer to the Backport tool documentation

@mohitjha-elastic mohitjha-elastic requested a review from a team as a code owner October 31, 2025 07:45
@elasticsearchmachine elasticsearchmachine added external-contributor Pull request authored by a developer outside the Elasticsearch team v9.1.7 labels Oct 31, 2025
@mohitjha-elastic mohitjha-elastic self-assigned this Oct 31, 2025
@mohitjha-elastic mohitjha-elastic added >non-issue :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Security Meta label for security team auto-merge-without-approval Automatically merge pull request when CI checks pass (NB doesn't wait for reviews!) Team:Cloud Security Meta label for Cloud Security team labels Oct 31, 2025
… event (elastic#137222)

This PR introduces a short-term solution by adding the logs-sentinel_one.threat_event-* indices to the kibana_system role with delete privileges. This prevents deletion failures when the index enters the ILM deletion phase. Since the transform pipeline is also shipped as part of this change, the role requires additional read and write permissions.

(cherry picked from commit ddb1502)
Copy link
Member

@azasypkin azasypkin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mirroring my LGTM from the PR for main.

@mohitjha-elastic mohitjha-elastic merged commit 834fbc0 into elastic:9.1 Nov 4, 2025
42 of 43 checks passed
@mohitjha-elastic mohitjha-elastic deleted the backport/9.1/pr-137222 branch November 4, 2025 08:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-merge-without-approval Automatically merge pull request when CI checks pass (NB doesn't wait for reviews!) backport external-contributor Pull request authored by a developer outside the Elasticsearch team >non-issue :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Cloud Security Meta label for Cloud Security team Team:Security Meta label for security team v9.1.7

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants