Skip to content

Conversation

@mohitjha-elastic
Copy link
Contributor

Backport

This will backport the following commits from main to 8.19:

Questions ?

Please refer to the Backport tool documentation

… event (elastic#137222)

This PR introduces a short-term solution by adding the logs-sentinel_one.threat_event-* indices to the kibana_system role with delete privileges. This prevents deletion failures when the index enters the ILM deletion phase. Since the transform pipeline is also shipped as part of this change, the role requires additional read and write permissions.

(cherry picked from commit ddb1502)

# Conflicts:
#	x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/security/authz/store/KibanaOwnedReservedRoleDescriptors.java
@elasticsearchmachine elasticsearchmachine added v8.19.7 external-contributor Pull request authored by a developer outside the Elasticsearch team labels Oct 31, 2025
@mohitjha-elastic mohitjha-elastic self-assigned this Oct 31, 2025
@mohitjha-elastic mohitjha-elastic added >non-issue :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Security Meta label for security team auto-merge-without-approval Automatically merge pull request when CI checks pass (NB doesn't wait for reviews!) Team:Cloud Security Meta label for Cloud Security team labels Oct 31, 2025
Copy link
Member

@azasypkin azasypkin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mirroring my LGTM from the PR for main.

@mohitjha-elastic mohitjha-elastic merged commit d652165 into elastic:8.19 Nov 3, 2025
24 of 25 checks passed
@mohitjha-elastic mohitjha-elastic deleted the backport/8.19/pr-137222 branch November 3, 2025 09:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-merge-without-approval Automatically merge pull request when CI checks pass (NB doesn't wait for reviews!) backport external-contributor Pull request authored by a developer outside the Elasticsearch team >non-issue :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Cloud Security Meta label for Cloud Security team Team:Security Meta label for security team v8.19.7

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants