Adding agent exclusion filters to dga, lmd and problemchild packages - #13058
Conversation
sodhikirti07
left a comment
There was a problem hiding this comment.
@mgarzon The filters for DGA and problemchild look good. You'll need to add filter to the LMD jobs that aren't RDP based. Also, please bump the versions of manifest.yml and changelog.yml as well as transform.yml where necessary.
susan-shu-c
left a comment
There was a problem hiding this comment.
Thanks for addressing comments from Kirti; this looks good to me
sodhikirti07
left a comment
There was a problem hiding this comment.
Changes look good to me! Did you try testing the packages locally? If so, could you please add screenshots?
|
Pinging @elastic/sec-applied-ml (Team:Security-Applied ML) |
Fixed indentation problem.
|
💚 Build Succeeded
History
|
|
Package dga - 2.3.0 containing this change is available at https://epr.elastic.co/package/dga/2.3.0/ |
|
Package lmd - 2.4.0 containing this change is available at https://epr.elastic.co/package/lmd/2.4.0/ |
|
Package problemchild - 2.4.0 containing this change is available at https://epr.elastic.co/package/problemchild/2.4.0/ |
…13058) * Adding agent exclusion filters to dga, lmd and problemchild packages * increasing version numbers and adding filters to datafeeds of lmd * Filters in lmd-ml.json are not needed as they have been added to transform
…13058) * Adding agent exclusion filters to dga, lmd and problemchild packages * increasing version numbers and adding filters to datafeeds of lmd * Filters in lmd-ml.json are not needed as they have been added to transform
…13058) * Adding agent exclusion filters to dga, lmd and problemchild packages * increasing version numbers and adding filters to datafeeds of lmd * Filters in lmd-ml.json are not needed as they have been added to transform
…13058) * Adding agent exclusion filters to dga, lmd and problemchild packages * increasing version numbers and adding filters to datafeeds of lmd * Filters in lmd-ml.json are not needed as they have been added to transform


As described in https://github.com/elastic/security-team/issues/11532, we have added filters to exclude any processing related to the elastic endpoint agents.