Skip to content

[microsoft_defender_endpoint] Add machine and machine action data streams - #13523

Merged
efd6 merged 3 commits into
elastic:mainfrom
brijesh-elastic:microsoft_defender_endpoint-2.33.0
Apr 14, 2025
Merged

[microsoft_defender_endpoint] Add machine and machine action data streams#13523
efd6 merged 3 commits into
elastic:mainfrom
brijesh-elastic:microsoft_defender_endpoint-2.33.0

Conversation

@brijesh-elastic

@brijesh-elastic brijesh-elastic commented Apr 12, 2025

Copy link
Copy Markdown
Contributor

Proposed commit message

microsoft_defender_endpoint: add support for machine and machine_action data streams

This update adds support for machine and machine action logs to enhance
data ingestion, enabling improved bidirectional response actions.

Sanitized test case inputs were obtained from live Microsoft Defender
for Endpoint instance using the Machine API and Machine Action API.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

  • Clone integrations repo.
  • Install elastic package locally.
  • Start elastic stack using elastic-package.
  • Move to integrations/packages/microsoft_defender_endpoint directory.
  • Run the following command to run tests.

elastic-package test

Related issues

Screenshots

Machine Overview
Machine Action Overview

@brijesh-elastic brijesh-elastic added enhancement New feature or request Integration:microsoft_defender_endpoint Microsoft Defender for Endpoint Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] labels Apr 12, 2025
@brijesh-elastic brijesh-elastic self-assigned this Apr 12, 2025
@brijesh-elastic
brijesh-elastic requested a review from a team as a code owner April 12, 2025 18:04
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggest this for the commit message (the API docs are already referenced in the change, so they don't need to be in the commit message, but also, no markdown in git logs, and wrap)

microsoft_defender_endpoint: add support for machine and machine_action data streams

This update adds support for machine and machine action logs to enhance
data ingestion, enabling improved bidirectional response actions.

Sanitized test case inputs were obtained from live Microsoft Defender
for Endpoint instance using the Machine API and Machine Action API.
Comment thread packages/microsoft_defender_endpoint/_dev/build/docs/README.md Outdated
@brijesh-elastic
brijesh-elastic requested a review from efd6 April 14, 2025 06:01
@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @brijesh-elastic

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@efd6
efd6 merged commit 17f5c4e into elastic:main Apr 14, 2025
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package microsoft_defender_endpoint - 2.33.0 containing this change is available at https://epr.elastic.co/package/microsoft_defender_endpoint/2.33.0/

@andrewkroh andrewkroh added the dashboard Relates to a Kibana dashboard bug, enhancement, or modification. label Apr 14, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dashboard Relates to a Kibana dashboard bug, enhancement, or modification. enhancement New feature or request Integration:microsoft_defender_endpoint Microsoft Defender for Endpoint Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

4 participants