Repository navigation
[first_epss] Add latest transform for ES|QL LOOKUP JOIN enrichment - #21843
Conversation
…ansform that supports deduplicated EPSS score lookups per CVE.
…by adding external references and creating new YAML files for latest vulnerability fields and input types.
…ta processing, enabling deduplicated EPSS score lookups per CVE.
…OKUP JOIN, explaining the latest transform for deduplicated EPSS score lookups per CVE.
Update the changelog link from the fork issue to elastic#21843. Co-authored-by: Cursor <cursoragent@cursor.com>
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
Address Vale Elastic.Semicolons suggestion on the query-time enrichment section. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The documented alias query fails on supported Elasticsearch 9.0 deployments without the concrete-index fallback.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds a latest-state lookup transform for query-time EPSS enrichment by CVE.
Changes:
- Creates and maps the lookup-mode transform destination.
- Documents ES|QL enrichment usage.
- Bumps the package version and changelog.
| File | Description |
|---|---|
packages/first_epss/manifest.yml |
Bumps package and format versions. |
packages/first_epss/elasticsearch/transform/latest_vulnerability/transform.yml |
Defines latest-CVE transform behavior. |
packages/first_epss/elasticsearch/transform/latest_vulnerability/manifest.yml |
Configures the lookup index template. |
packages/first_epss/elasticsearch/transform/latest_vulnerability/fields/is-transform-source-false.yml |
Marks transform output documents. |
packages/first_epss/elasticsearch/transform/latest_vulnerability/fields/fields.yml |
Maps EPSS output fields. |
packages/first_epss/elasticsearch/transform/latest_vulnerability/fields/beats.yml |
Maps the input type field. |
packages/first_epss/elasticsearch/transform/latest_vulnerability/fields/base-fields.yml |
Defines base transform fields. |
packages/first_epss/docs/README.md |
Adds generated enrichment documentation. |
packages/first_epss/data_stream/vulnerability/fields/base-fields.yml |
Uses ECS base-field definitions. |
packages/first_epss/changelog.yml |
Records the 1.6.0 enhancement. |
packages/first_epss/_dev/build/docs/README.md |
Adds source enrichment documentation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
| enable_request_tracer: true | ||
| assert: | ||
| hit_count: 3 No newline at end of file | ||
| hit_count: 3 |
There was a problem hiding this comment.
Severity: 🔵 Low confidence: medium path: packages/cisa_kevs/data_stream/vulnerability/_dev/test/system/test-default-config.yml:9
This PR touches an unrelated package (cisa_kevs) with a trailing-newline-only change; drop it from this PR so the first_epss change stays self-contained and does not pull cisa_kevs into this PR's CI run.
Details
The only change to packages/cisa_kevs/...test-default-config.yml is adding a trailing newline. It has no functional effect, is not mentioned in the PR description or any changelog, and causes CI to treat cisa_kevs as an affected package for this PR (see is_pr_affected in .buildkite/scripts/common.sh). It looks like an accidental artifact of running a repo-wide formatter.
Recommendation:
Revert the file to its main state in this PR, or if the formatter fix is wanted, land it in a separate trivial PR:
git checkout origin/main -- packages/cisa_kevs/data_stream/vulnerability/_dev/test/system/test-default-config.yml🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills
⚠️ Automated review — verify suggestions before applying.
🚀 Benchmarks reportTo see the full report comment with |
| "name": "elastic-agent-99127", | ||
| "type": "filebeat", | ||
| "version": "8.13.0" | ||
| "version": "9.5.4" |
There was a problem hiding this comment.
Severity: 🟡 Medium confidence: high path: packages/cisa_kevs/docs/README.md:65
Regenerated cisa_kevs artifacts (docs/README.md sample event, sample_event.json, pipeline expected output, test config newline) are included without a cisa_kevs version bump or changelog entry; revert all packages/cisa_kevs changes from this PR.
Details
The PR modifies packages/cisa_kevs/docs/README.md (sample event: agent ids, agent version 8.13.0 -> 9.5.4, namespace, event.ingested, date rendering), sample_event.json, the pipeline expected output, and _dev/test/system/test-default-config.yml (trailing newline only). None of these relate to the first_epss transform; they are byproducts of running the cisa_kevs test suite locally on a newer stack. The cisa_kevs manifest.yml and changelog.yml are untouched, so package content changes without a version bump, contrary to the repository convention that every package content change ships with a bump and changelog entry, and the change pulls cisa_kevs owners into an unrelated review. Prior bot finding 6131f1ef2ab5d30f raised the newline-only change; the README and sample event regeneration are new since that review (they appear as added lines in the re-review delta), so this extends that finding rather than repeating it. Also note the PR description says the transform mirrors an existing cisa_kevs lookup transform, but packages/cisa_kevs has no elasticsearch/transform/ directory in this checkout; hackerone and qualys_gav are the actual precedents.
Recommendation:
Revert the cisa_kevs files to their main state:
git checkout origin/main -- packages/cisa_kevsIf the cisa_kevs sample refresh is wanted, land it separately with its own version bump and changelog entry.
🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills
⚠️ Automated review — verify suggestions before applying.
efd6
left a comment
There was a problem hiding this comment.
This needs an elastic-package build. Also, please amend the proposed commit message to remove markdown and have the commit message body be prose rather than a WHAT/WHY-bulleted list.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
591a150 to
3aa889a
Compare
|
✅ All changelog entries have the correct PR link. |
|
🟢 Reviewed the latest commits 3aa889a (history rewritten since 591a150) — nothing new beyond already posted comments.
|
💚 Build Succeeded
History
|
|
@efd6 it should be fine now. Can you please review again and merge as well if it's fine. Thank you. |
Backport branchesImportant Only active backport branches for packages changed by this PR are shown. Tick the branches you want to backport to. A backport PR will be opened automatically for each branch you check. Backport a change when it fixes behavior a branch already has; leave new behavior on aws
tenable_io
ti_abusech
Tip If a branch above is no longer required, set |
|
Package first_epss - 1.6.0 containing this change is available at https://epr.elastic.co/package/first_epss/1.6.0/ |


Proposed commit message
Adds a
latestElasticsearch transform (latest_vulnerability) to thefirst_epssintegration that deduplicates the re-ingested EPSS catalog into one row per CVE, writing the result to a lookup-mode destination index aliased aslogs-first_epss_latest.vulnerability.The FIRST.org feed re-ingests its full catalog on every poll cycle, so the same CVE repeats with updated scores in
logs-first_epss.vulnerability-*. Collapsing those snapshots into a lookup index lets users enrich vulnerability findings at query time with the ES|QLLOOKUP JOINcommand onvulnerability.id.The transform dedups on
vulnerability.id, sorts byevent.ingestedto keep the latest score, and excludes cold/frozen tier copies since the full catalog re-ingests each cycle anyway. It mirrors the existingcisa_kevs,hackerone, andqualys_gavlookup-transform pattern.The package
format_versionis bumped to3.6.6to supportindex.mode: lookup, and the package version is bumped to1.6.0.Checklist
changelog.ymlfile.How to test this PR locally
From
packages/first_epss/:After install, confirm the
logs-first_epss_latest.vulnerabilitytransform runs and smoke-test a join: