Skip to content

[first_epss] Add latest transform for ES|QL LOOKUP JOIN enrichment - #21843

Merged
efd6 merged 10 commits into
elastic:mainfrom
clement-fouque:feat/first_epss-latest-transform
Oct 7, 2026
Merged

efd6 merged 10 commits into
elastic:mainfrom
clement-fouque:feat/first_epss-latest-transform

Conversation

@clement-fouque

@clement-fouque clement-fouque commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Proposed commit message

Adds a latest Elasticsearch transform (latest_vulnerability) to the first_epss integration that deduplicates the re-ingested EPSS catalog into one row per CVE, writing the result to a lookup-mode destination index aliased as logs-first_epss_latest.vulnerability.

The FIRST.org feed re-ingests its full catalog on every poll cycle, so the same CVE repeats with updated scores in logs-first_epss.vulnerability-*. Collapsing those snapshots into a lookup index lets users enrich vulnerability findings at query time with the ES|QL LOOKUP JOIN command on vulnerability.id.

The transform dedups on vulnerability.id, sorts by event.ingested to keep the latest score, and excludes cold/frozen tier copies since the full catalog re-ingests each cycle anyway. It mirrors the existing cisa_kevs, hackerone, and qualys_gav lookup-transform pattern.

The package format_version is bumped to 3.6.6 to support index.mode: lookup, and the package version is bumped to 1.6.0.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

From packages/first_epss/:

elastic-package format
elastic-package lint
elastic-package check
elastic-package build
elastic-package test static

# With a running stack
elastic-package stack up -d
elastic-package test asset
elastic-package test system --data-streams vulnerability

After install, confirm the logs-first_epss_latest.vulnerability transform runs and smoke-test a join:

FROM logs-endpoint.vulnerability-*
| LOOKUP JOIN logs-first_epss_latest.vulnerability ON vulnerability.id
| KEEP vulnerability.id, first_epss.vulnerability.epss, first_epss.vulnerability.percentile, first_epss.vulnerability.date
| WHERE first_epss.vulnerability.epss IS NOT NULL

LOOKUP JOIN against a lookup-mode index requires Elasticsearch 9.1+. On older stacks, target the concrete destination index logs-first_epss_latest.dest_vulnerability-1.

clement-fouque and others added 6 commits October 2, 2026 15:43
…ansform that supports deduplicated EPSS score lookups per CVE.
…by adding external references and creating new YAML files for latest vulnerability fields and input types.
…ta processing, enabling deduplicated EPSS score lookups per CVE.
…OKUP JOIN, explaining the latest transform for deduplicated EPSS score lookups per CVE.
Update the changelog link from the fork issue to elastic#21843.

Co-authored-by: Cursor <cursoragent@cursor.com>
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@clement-fouque
clement-fouque marked this pull request as ready for review October 2, 2026 14:09
@clement-fouque
clement-fouque requested review from a team as code owners October 2, 2026 14:09
Copilot AI balanced review requested due to automatic review settings October 2, 2026 14:09
Address Vale Elastic.Semicolons suggestion on the query-time enrichment section.

Co-authored-by: Cursor <cursoragent@cursor.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The documented alias query fails on supported Elasticsearch 9.0 deployments without the concrete-index fallback.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Adds a latest-state lookup transform for query-time EPSS enrichment by CVE.

Changes:

  • Creates and maps the lookup-mode transform destination.
  • Documents ES|QL enrichment usage.
  • Bumps the package version and changelog.
File Description
packages/​first_epss/​manifest.yml Bumps package and format versions.
packages/​first_epss/​elasticsearch/​transform/​latest_vulnerability/​transform.yml Defines latest-CVE transform behavior.
packages/​first_epss/​elasticsearch/​transform/​latest_vulnerability/​manifest.yml Configures the lookup index template.
packages/​first_epss/​elasticsearch/​transform/​latest_vulnerability/​fields/​is-transform-source-false.yml Marks transform output documents.
packages/​first_epss/​elasticsearch/​transform/​latest_vulnerability/​fields/​fields.yml Maps EPSS output fields.
packages/​first_epss/​elasticsearch/​transform/​latest_vulnerability/​fields/​beats.yml Maps the input type field.
packages/​first_epss/​elasticsearch/​transform/​latest_vulnerability/​fields/​base-fields.yml Defines base transform fields.
packages/​first_epss/​docs/​README.md Adds generated enrichment documentation.
packages/​first_epss/​data_stream/​vulnerability/​fields/​base-fields.yml Uses ECS base-field definitions.
packages/​first_epss/​changelog.yml Records the 1.6.0 enhancement.
packages/​first_epss/​_dev/​build/​docs/​README.md Adds source enrichment documentation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages/first_epss/_dev/build/docs/README.md
Copilot AI balanced review requested due to automatic review settings October 2, 2026 14:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The documented alias query fails on supported pre-9.1 Elasticsearch versions without the concrete-index fallback.

Review effort: Balanced
Findings: 1 Low severity

Open (1)

@qcorporation qcorporation added Integration:first_epss First EPSS (Community supported) documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] enhancement New feature or request labels Oct 3, 2026
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

Copilot AI balanced review requested due to automatic review settings October 5, 2026 07:52
enable_request_tracer: true
assert:
hit_count: 3 No newline at end of file
hit_count: 3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Severity: 🔵 Low confidence: medium path: packages/cisa_kevs/data_stream/vulnerability/_dev/test/system/test-default-config.yml:9

This PR touches an unrelated package (cisa_kevs) with a trailing-newline-only change; drop it from this PR so the first_epss change stays self-contained and does not pull cisa_kevs into this PR's CI run.

Details

The only change to packages/cisa_kevs/...test-default-config.yml is adding a trailing newline. It has no functional effect, is not mentioned in the PR description or any changelog, and causes CI to treat cisa_kevs as an affected package for this PR (see is_pr_affected in .buildkite/scripts/common.sh). It looks like an accidental artifact of running a repo-wide formatter.

Recommendation:

Revert the file to its main state in this PR, or if the formatter fix is wanted, land it in a separate trivial PR:

git checkout origin/main -- packages/cisa_kevs/data_stream/vulnerability/_dev/test/system/test-default-config.yml

🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills

⚠️ Automated review — verify suggestions before applying.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The generated README is missing documentation generated from the new transform and field assets.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
Resolved since last review (1)

Comment thread packages/first_epss/docs/README.md
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@qcorporation qcorporation added the Integration:cisa_kevs CISA Known Exploited Vulnerabilities (Community supported) label Oct 5, 2026
Copilot AI balanced review requested due to automatic review settings October 5, 2026 22:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Comment thread packages/cisa_kevs/docs/README.md Outdated
"name": "elastic-agent-99127",
"type": "filebeat",
"version": "8.13.0"
"version": "9.5.4"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Severity: 🟡 Medium confidence: high path: packages/cisa_kevs/docs/README.md:65

Regenerated cisa_kevs artifacts (docs/README.md sample event, sample_event.json, pipeline expected output, test config newline) are included without a cisa_kevs version bump or changelog entry; revert all packages/cisa_kevs changes from this PR.

Details

The PR modifies packages/cisa_kevs/docs/README.md (sample event: agent ids, agent version 8.13.0 -> 9.5.4, namespace, event.ingested, date rendering), sample_event.json, the pipeline expected output, and _dev/test/system/test-default-config.yml (trailing newline only). None of these relate to the first_epss transform; they are byproducts of running the cisa_kevs test suite locally on a newer stack. The cisa_kevs manifest.yml and changelog.yml are untouched, so package content changes without a version bump, contrary to the repository convention that every package content change ships with a bump and changelog entry, and the change pulls cisa_kevs owners into an unrelated review. Prior bot finding 6131f1ef2ab5d30f raised the newline-only change; the README and sample event regeneration are new since that review (they appear as added lines in the re-review delta), so this extends that finding rather than repeating it. Also note the PR description says the transform mirrors an existing cisa_kevs lookup transform, but packages/cisa_kevs has no elasticsearch/transform/ directory in this checkout; hackerone and qualys_gav are the actual precedents.

Recommendation:

Revert the cisa_kevs files to their main state:

git checkout origin/main -- packages/cisa_kevs

If the cisa_kevs sample refresh is wanted, land it separately with its own version bump and changelog entry.


🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills

⚠️ Automated review — verify suggestions before applying.

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This needs an elastic-package build. Also, please amend the proposed commit message to remove markdown and have the commit message body be prose rather than a WHAT/WHY-bulleted list.

Copilot AI balanced review requested due to automatic review settings October 6, 2026 20:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The unrelated cisa_kevs changes should be reverted or released separately with appropriate metadata.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)

Comment thread packages/cisa_kevs/data_stream/vulnerability/sample_event.json Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 20:42
@clement-fouque
clement-fouque force-pushed the feat/first_epss-latest-transform branch from 591a150 to 3aa889a Compare October 6, 2026 20:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The transform, mappings, package metadata, and documentation consistently implement the established lookup-index pattern.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

✅ All changelog entries have the correct PR link.

@vera-review-bot

Copy link
Copy Markdown

🟢 Reviewed the latest commits 3aa889a (history rewritten since 591a150) — nothing new beyond already posted comments.

⚠️ 2 comments still unresolved from earlier commits — 1 medium, 1 low
  • 🟡 Regenerated cisa_kevs artifacts (docs/README.md sample event, sample_event.json, pipeline expected output, test config newline) are included without a cisa_kevs version bump or changelog entry (link)
  • 🔵 This PR touches an unrelated package (cisa_kevs) with a trailing-newline-only change (link)

Review summary

Issues found across earlier commits f046209 — 1 medium
  • 🟡 Regenerated cisa_kevs artifacts (docs/README.md sample event, sample_event.json, pipeline expected output, test config newline) are included without a cisa_kevs version bump or changelog entry (link) (Outdated)
Issues found across earlier commits c009ba3…4cb7418 (3 commits) — 1 low
  • 🔵 This PR touches an unrelated package (cisa_kevs) with a trailing-newline-only change (link) (Outdated)
Issues found across earlier commits 86fe356 — 1 medium, 2 low
  • 🟡 The lookup index declares no mapping for vulnerability.id (the LOOKUP JOIN key) or the other ECS fields the latest transform copies from source (link)
  • 🔵 The destination index is labelled labels.is_transform_source: "false" but the source data stream never sets the label to "true" (link)

Package-level:

  • 🔵 Proposed commit message

    first_epss: add latest transform for ES|QL LOOKUP JOIN enrichment
    
    Add a latest transform (latest_vulnerability) that collapses the
    re-ingested EPSS catalog into one document per CVE and writes it to a
    lookup-mode destination index, logs-first_epss_latest.dest_vulnerability-1,
    aliased as logs-first_epss_latest.vulnerability.
    
    The FIRST.org EPSS feed re-ingests the full catalog on every poll cycle,
    so the same CVE appears repeatedly in logs-first_epss.vulnerability-* with
    updated scores. Keeping only the latest row per CVE lets users enrich
    vulnerability findings at query time with the ES|QL LOOKUP JOIN command on
    vulnerability.id, which the ingest pipeline already sets from
    first_epss.vulnerability.cve.
    
    The transform deduplicates on vulnerability.id, sorts by event.ingested,
    excludes error documents and the cold and frozen tiers, and runs unattended
    with deduce_mappings disabled. The package format_version is raised to
    3.6.6 and the package version to 1.6.0.
    

A new commit triggers another review — at most once every 15 minutes. I skip the PR while it's approved or has merge conflicts.

🤖 AI-Generated Review | Vera Review Bot - v0.4.2 | 📚 Knowledge base: integration-skills

⚠️ Automated review — verify suggestions before applying.

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

History

@clement-fouque

Copy link
Copy Markdown
Contributor Author

@efd6 it should be fine now. Can you please review again and merge as well if it's fine. Thank you.

@efd6
efd6 merged commit c2bd350 into elastic:main Oct 7, 2026
16 checks passed
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Backport branches

Important

Only active backport branches for packages changed by this PR are shown.

Tick the branches you want to backport to. A backport PR will be opened automatically for each branch you check.

Backport a change when it fixes behavior a branch already has; leave new behavior on main. See when and why to backport if you are unsure.

aws

  • backport-aws-7.3
  • backport-aws-7.2
  • backport-aws-7.1
  • backport-aws-7.0
  • backport-aws-6.x (maintained until 2027-01-16)
  • backport-aws-3.17
  • backport-aws-3.13
  • backport-aws-2.30
  • backport-aws-2.25
  • backport-aws-2.24
  • backport-aws-1.51

tenable_io

  • backport-tenable_io-3.10

ti_abusech

  • backport-ti_abusech-2.6

Tip

If a branch above is no longer required, set archived: true in its entry in .backports.yml to stop it appearing here.
If the branch has a known end-of-life date, prefer maintained_until: "YYYY-MM-DD" — it will be excluded automatically once that date passes.

cc @clement-fouque @efd6

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package first_epss - 1.6.0 containing this change is available at https://epr.elastic.co/package/first_epss/1.6.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:cisa_kevs CISA Known Exploited Vulnerabilities (Community supported) Integration:first_epss First EPSS (Community supported) Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants