Skip to content

[watchguard_firebox] Initial release of the WatchGuard Firebox - #10110

Merged
taylor-swanson merged 8 commits into
elastic:mainfrom
brijesh-elastic:package-watchguard_firebox
Jul 11, 2024
Merged

[watchguard_firebox] Initial release of the WatchGuard Firebox#10110
taylor-swanson merged 8 commits into
elastic:mainfrom
brijesh-elastic:package-watchguard_firebox

Conversation

@brijesh-elastic

Copy link
Copy Markdown
Contributor

Proposed commit message

Create New integration package watchguard_firebox.

  • Added a log data stream.
  • Added data collection logic for log data stream.
  • Added the ingest pipeline for log data stream.
  • Mapped fields according to the ECS schema and added Fields metadata in the appropriate yml files.
  • Added dashboards and visualizations.
  • Added test for pipeline for log data stream.
  • Added system test cases for log data stream.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

How to test this PR locally

  • Clone integrations repo.
  • Install elastic package locally.
  • Start elastic stack using elastic-package.
  • Move to integrations/packages/watchguard_firebox directory.
  • Run the following command to run tests.

elastic-package test

--- Test results for package: watchguard_firebox - START ---
╭────────────────────┬─────────────┬───────────┬─────────────────────────────────────────────────────────────────────────────┬────────┬──────────────╮
│ PACKAGE            │ DATA STREAM │ TEST TYPE │ TEST NAME                                                                   │ RESULT │ TIME ELAPSED │
├────────────────────┼─────────────┼───────────┼─────────────────────────────────────────────────────────────────────────────┼────────┼──────────────┤
│ watchguard_firebox │             │ asset     │ dashboard watchguard_firebox-5fb58f2b-8720-4b57-89b6-0f727f0d260f is loaded │ PASS   │        882ns │
│ watchguard_firebox │             │ asset     │ search watchguard_firebox-0c03afcf-e39d-484a-8575-0630b7bb892a is loaded    │ PASS   │        308ns │
│ watchguard_firebox │             │ asset     │ search watchguard_firebox-19e90429-51c9-4f47-8889-baf56bdc7735 is loaded    │ PASS   │        237ns │
│ watchguard_firebox │             │ asset     │ search watchguard_firebox-5cbe635b-9d2e-4d14-b2d4-e7146c421eaf is loaded    │ PASS   │        195ns │
│ watchguard_firebox │             │ asset     │ search watchguard_firebox-9173ff94-4af2-4f6d-86bc-7123d0f335f5 is loaded    │ PASS   │        216ns │
│ watchguard_firebox │ log         │ asset     │ index_template logs-watchguard_firebox.log is loaded                        │ PASS   │        184ns │
│ watchguard_firebox │ log         │ asset     │ ingest_pipeline logs-watchguard_firebox.log-0.1.0 is loaded                 │ PASS   │        162ns │
╰────────────────────┴─────────────┴───────────┴─────────────────────────────────────────────────────────────────────────────┴────────┴──────────────╯
--- Test results for package: watchguard_firebox - END   ---
Done
--- Test results for package: watchguard_firebox - START ---
╭────────────────────┬─────────────┬───────────┬────────────────────────────┬────────┬──────────────╮
│ PACKAGE            │ DATA STREAM │ TEST TYPE │ TEST NAME                  │ RESULT │ TIME ELAPSED │
├────────────────────┼─────────────┼───────────┼────────────────────────────┼────────┼──────────────┤
│ watchguard_firebox │ log         │ pipeline  │ test-alarm.log             │ PASS   │  62.374853ms │
│ watchguard_firebox │ log         │ pipeline  │ test-diagnostic.log        │ PASS   │ 284.010886ms │
│ watchguard_firebox │ log         │ pipeline  │ test-event.log             │ PASS   │  153.26417ms │
│ watchguard_firebox │ log         │ pipeline  │ test-traffic.log           │ PASS   │ 230.823811ms │
│ watchguard_firebox │ log         │ pipeline  │ (ingest pipeline warnings) │ PASS   │ 264.588415ms │
╰────────────────────┴─────────────┴───────────┴────────────────────────────┴────────┴──────────────╯
--- Test results for package: watchguard_firebox - END   ---
Done
--- Test results for package: watchguard_firebox - START ---
╭────────────────────┬─────────────┬───────────┬──────────────────────────┬────────┬──────────────╮
│ PACKAGE            │ DATA STREAM │ TEST TYPE │ TEST NAME                │ RESULT │ TIME ELAPSED │
├────────────────────┼─────────────┼───────────┼──────────────────────────┼────────┼──────────────┤
│ watchguard_firebox │ log         │ static    │ Verify sample_event.json │ PASS   │ 134.419749ms │
╰────────────────────┴─────────────┴───────────┴──────────────────────────┴────────┴──────────────╯
--- Test results for package: watchguard_firebox - END   ---
Done
--- Test results for package: watchguard_firebox - START ---
╭────────────────────┬─────────────┬───────────┬───────────┬────────┬──────────────╮
│ PACKAGE            │ DATA STREAM │ TEST TYPE │ TEST NAME │ RESULT │ TIME ELAPSED │
├────────────────────┼─────────────┼───────────┼───────────┼────────┼──────────────┤
│ watchguard_firebox │ log         │ system    │ udp       │ PASS   │ 39.83772453s │
╰────────────────────┴─────────────┴───────────┴───────────┴────────┴──────────────╯
--- Test results for package: watchguard_firebox - END   ---
Done

Related issues

Screenshots

Integration Page
Overview Page

@elasticmachine

Copy link
Copy Markdown

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@kcreddy kcreddy added New Integration Issue or pull request for creating a new integration package. Crest Contributions from Crest developement team. Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Jun 11, 2024
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

"procid": "10"
}
},
"message": "Cannot relearn system MAC address, possible loop or MAC spoofing, ip=192.168.111.10, mac=00:50:da:c7:90:5d, interface=5",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For 3000012E, the doc describes the mac as observer mac address. We could copy this into observer.mac

"procid": "10"
}
},
"message": "[eth0] Sending interface status event, logical=up link=up ip=10.0.0.1 mask=81.2.69.144",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could add mask to related.ip

Comment on lines +2368 to +2374
"dns": {
"question": {
"name": "members.dyndns.org"
},
"resolved_ip": [
"81.2.69.144"
]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add dns.type:answer

"procid": "10"
}
},
"message": "Received reply: HTTP/1.1 200 OK Date: Tue, 27 Nov 2012 17:14:57 GMT Server: Apache Content-Type: text/plain Connection: close good 192.168.53.88",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you parse them into http.* fields?

"procid": "10"
}
},
"message": "Received reply: HTTP/1.1 200 OK Date: Tue, 27 Nov 2012 17:14:57 GMT Server: Apache Content-Type: text/plain Connection: close good 192.168.53.88",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add IP address to related.ip

]
},
"rule": {
"name": "\"FTP-00\""

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you remove escape characters

@jamiehynds jamiehynds added the Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices] label Jun 11, 2024
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)

@jamiehynds jamiehynds removed the Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] label Jun 11, 2024
Comment thread .github/CODEOWNERS Outdated
/packages/universal_profiling_symbolizer @elastic/obs-ds-intake-services
/packages/vectra_detect @elastic/security-service-integrations
/packages/vsphere @elastic/obs-infraobs-integrations
/packages/watchguard_firebox @elastic/security-service-integrations

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This integration will actually be owned by the @elastic/sec-deployment-and-devices team - can we ensure that's reflected in the codeowners please.

@taylor-swanson taylor-swanson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For performance and maintainability reasons, the large groks should be split out into individual processors for each log type.

  • Log types that extract back out to the same field need no additional processing (3000-0006 from pipeline_diagnostic, for example)
  • Use dissect first. It is faster than grok and in most cases can handle the patterns I see without issue
  • If dissect is not flexible enough, then grok can be used.

@taylor-swanson taylor-swanson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm still reviewing, but wanted to get some comments out in the mean time.

Also, please add the file kibana/tags.yml with the following contents:

- text: Security Solution
  asset_types:
    - dashboard
    - search

For example: https://github.com/elastic/integrations/blob/main/packages/cisco_asa/kibana/tags.yml

Comment thread packages/watchguard_firebox/manifest.yml
Comment thread packages/watchguard_firebox/manifest.yml
Comment thread packages/watchguard_firebox/data_stream/log/fields/fields.yml Outdated
tag: rename_message_to_event_original
target_field: event.original
ignore_missing: true
description: Renames the original `message` field to `event.original` to store a copy of the original message. The `event.original` field is not touched if the document already has one; it may happen when Logstash sends the document.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The problem with this is logstash may attach an event.original that is not formatted correctly. We've actually started overwriting event.original with message in other integrations.

One such PR that addressed this was #9438, however, it doesn't go into detail about what the problem is. Basically, there was a case where logstash was putting the entire beat event document into event.original, rather than the original message from the vendor appliance.

So basically, we want this:

  - set:
      field: event.original
      copy_from: message
  - remove:
      field: message

@taylor-swanson taylor-swanson Jul 1, 2024

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is still outstanding.

Edit: Disregard, there are some issues with package-spec validation at later versions. I'll have to think of a different way of handling this, but it'll come in the form of a wider change that'll affect other integrations as well.

@kcreddy kcreddy left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM (for my comments) 👍🏼

@taylor-swanson taylor-swanson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just the message/event.original comment, otherwise everything else LGTM

tag: rename_message_to_event_original
target_field: event.original
ignore_missing: true
description: Renames the original `message` field to `event.original` to store a copy of the original message. The `event.original` field is not touched if the document already has one; it may happen when Logstash sends the document.

@taylor-swanson taylor-swanson Jul 1, 2024

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is still outstanding.

Edit: Disregard, there are some issues with package-spec validation at later versions. I'll have to think of a different way of handling this, but it'll come in the form of a wider change that'll affect other integrations as well.

@taylor-swanson taylor-swanson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

@taylor-swanson
taylor-swanson merged commit d6d9979 into elastic:main Jul 11, 2024
@elasticmachine

Copy link
Copy Markdown

Package watchguard_firebox - 0.1.0 containing this change is available at https://epr.elastic.co/search?package=watchguard_firebox

@andrewkroh andrewkroh added the Integration:watchguard_firebox WatchGuard Firebox label Jul 22, 2024
orestisfl pushed a commit to orestisfl/integrations that referenced this pull request May 15, 2026
…ic#10110)

- Created a new integration package for WatchGuard Firebox.
- Added a log data stream.
- Added data collection logic for log data stream.
- Added the ingest pipeline for log data stream.
- Mapped fields according to the ECS schema and added Fields metadata in the appropriate yml files.
- Added dashboards and visualizations.
- Added test for pipeline for log data stream.
- Added system test cases for log data stream.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Crest Contributions from Crest developement team. Integration:watchguard_firebox WatchGuard Firebox New Integration Issue or pull request for creating a new integration package. Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]

6 participants