# Running integration tests for a specific integration

**URL:** <https://discuss.elastic.co/t/running-integration-tests-for-a-specific-integration/370140>\
**Category:** Beats\
**Tags:** beats-development, filebeat\
**Created:** [November 6, 2024, 8:55pm UTC](https://discuss.elastic.co/t/running-integration-tests-for-a-specific-integration/370140 "2024-11-06T20:55:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jason26](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason26/32/54948_2.png) [@jason26](https://discuss.elastic.co/u/jason26)\
**Post date:** [November 6, 2024, 8:55pm UTC](https://discuss.elastic.co/t/running-integration-tests-for-a-specific-integration/370140/1 "2024-11-06T20:55:30Z")

</div>

Hi All,

I'm trying to update some mappings for an Elastic Agent integration, specifically Suricata. I see some test input files and expected output files, but I haven't found a test that actually uses them.

I've tried the tests outline in the testing guide ([Testing | Beats Developer Guide [master] | Elastic](https://www.elastic.co/guide/en/beats/devguide/current/testing.html)), but it doesn't appear execute the Suricata integration tests, am I missing something?

I'm hoping to update the mappings and test without deploying the full stack and doing trial and error.

Thanks!

---

<div class="post-metadata">

**Author:** ![Quan.Nguyen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quan.nguyen/32/136581_2.png) [@Quan.Nguyen](https://discuss.elastic.co/u/Quan.Nguyen)\
**Post date:** [November 6, 2024, 9:15pm UTC](https://discuss.elastic.co/t/running-integration-tests-for-a-specific-integration/370140/2 "2024-11-06T21:15:56Z")

</div>

Hi Jason,  
Thank you for the question. For the Suricata, if you want to update the ingest pipeline and parsing logic, your best bet is to use `elastic-package` to run the system and pipeline tests. There is [documentation online](https://www.elastic.co/guide/en/integrations-developer/current/testing.html) on how to run these tests.

Quickly, you'd bring up the stack locally  
`elastic-package stack up -d`  
navigate on the command line to `./packages/suricata` (within the `elastic/integrations` repo) and then run either the system  
`elastic-package test system -v`  
or the pipeline tests  
`elastic-package test pipeline -v`

---

<div class="post-metadata">

**Author:** ![jason26](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason26/32/54948_2.png) [@jason26](https://discuss.elastic.co/u/jason26)\
**Post date:** [November 6, 2024, 11:07pm UTC](https://discuss.elastic.co/t/running-integration-tests-for-a-specific-integration/370140/3 "2024-11-06T23:07:38Z")

</div>

Thanks, I'm now able to make a simple test fail. So integrations from this repo land in beats/agent?

---

<div class="post-metadata">

**Author:** ![Quan.Nguyen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quan.nguyen/32/136581_2.png) [@Quan.Nguyen](https://discuss.elastic.co/u/Quan.Nguyen)\
**Post date:** [November 7, 2024, 6:08pm UTC](https://discuss.elastic.co/t/running-integration-tests-for-a-specific-integration/370140/4 "2024-11-07T18:08:32Z")

</div>

The integration pipeline is multi-element, there's beats that does enrichment, there's also an ingest pipeline that gets installed and is a destination for when agent sends data to elasticsearch. The code within `elastic/integrations` is released out of band from the stack release and consists of configuration that can be done to agent/beats, configuration of the ingest pipeline and visual assets.

So to answer your question, no. `elastic/integrations` works in conjunction of the beats/agent repo
