Skip to content

feat: replace log/logx bag with event (flattened) + add controls field #2791

Description

@osmontero

Problem

Logs carrying fields that do not fit the standard UTMStack typed fields are stored under log (a heterogeneous map). OpenSearch dynamic mapping infers a hard type for each key on first sight and rejects any later value that does not fit (mapper_parsing_exception), so the log is lost.

Approach (planned)

  • New canonical bag event replacing log.* / legacy logx.*, mapped as OpenSearch flattened (keyword sub-values, no type inference, no conflicts possible).
  • New controls []string field reserved for compliance control tags (populated later by the compliance orchestrator).
  • Rename cascades from the go-sdk proto (Event field 9 log -> event, new field 20 controls) through EventProcessor parsing, UTMStack filters/rules, installer index template, backend SearchUtil (flattened-aware query building), user-auditor, and the frontend (file-management module moves to origin/target canonical fields).
  • No reindex: new data uses event; old log data rides out ILM rotation.

Scope

Coordinated cross-repo change: threatwinds/go-sdk, utmstack/EventProcessor, utmstack/UTMStack (filters, rules, installer, backend, user-auditor, frontend, alerts plugin tests).

Plan: UTMStack repo docs/plans/2026-09-30-event-bag-rename.md.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions