Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions packages/crowdstrike/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.34.2"
changes:
- description: Resolved ignore_malformed issues with fields.
type: bugfix
link: https://github.com/elastic/integrations/pull/9832
- version: "1.34.1"
changes:
- description: Improve error handling for renaming processors.
Expand Down
6 changes: 3 additions & 3 deletions packages/crowdstrike/data_stream/fdr/fields/fields.yml
Original file line number Diff line number Diff line change
Expand Up @@ -527,7 +527,7 @@
- name: ConfigIDPlatform
type: keyword
- name: ConfigStateData
type: keyword
type: text
- name: ConfigurationVersion
type: keyword
- name: ConnectTime
Expand Down Expand Up @@ -565,7 +565,7 @@
- name: FeatureExtractionVersion
type: keyword
- name: FeatureVector
type: keyword
type: match_only_text
- name: File
type: keyword
- name: FirmwareAnalysisEclConsumerInterfaceVersion
Expand Down Expand Up @@ -633,7 +633,7 @@
- name: NetworkContainmentState
type: keyword
- name: OSVersionFileData
type: keyword
type: match_only_text
- name: OSVersionFileName
type: keyword
- name: OutErrors
Expand Down
6 changes: 3 additions & 3 deletions packages/crowdstrike/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -1217,7 +1217,7 @@ and/or `session_token`.
| crowdstrike.ConfigIDBase | | keyword |
| crowdstrike.ConfigIDBuild | | keyword |
| crowdstrike.ConfigIDPlatform | | keyword |
| crowdstrike.ConfigStateData | | keyword |
| crowdstrike.ConfigStateData | | text |
| crowdstrike.ConfigStateHash | | keyword |
| crowdstrike.ConfigurationVersion | | keyword |
| crowdstrike.ConnectTime | | date |
Expand Down Expand Up @@ -1267,7 +1267,7 @@ and/or `session_token`.
| crowdstrike.FalconGroupingTags | | keyword |
| crowdstrike.FalconHostLink | | keyword |
| crowdstrike.FeatureExtractionVersion | | keyword |
| crowdstrike.FeatureVector | | keyword |
| crowdstrike.FeatureVector | | match_only_text |
| crowdstrike.File | | keyword |
| crowdstrike.FileAttributes | | keyword |
| crowdstrike.FileDeletedCount | | long |
Expand Down Expand Up @@ -1364,7 +1364,7 @@ and/or `session_token`.
| crowdstrike.NewExecutableWrittenCount | | long |
| crowdstrike.NewFileIdentifier | | keyword |
| crowdstrike.Nonce | | integer |
| crowdstrike.OSVersionFileData | | keyword |
| crowdstrike.OSVersionFileData | | match_only_text |
| crowdstrike.OSVersionFileName | | keyword |
| crowdstrike.OU | | keyword |
| crowdstrike.Objective | | keyword |
Expand Down
2 changes: 1 addition & 1 deletion packages/crowdstrike/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: crowdstrike
title: CrowdStrike
version: "1.34.1"
version: "1.34.2"
description: Collect logs from Crowdstrike with Elastic Agent.
type: integration
format_version: "3.0.3"
Expand Down
5 changes: 5 additions & 0 deletions packages/fortinet_fortimanager/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "2.11.1"
changes:
- description: Resolved ignore_malformed issues with fields.
type: bugfix
link: https://github.com/elastic/integrations/pull/9832
- version: "2.11.0"
changes:
- description: Update package spec to 3.0.3.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@
type: keyword
description: Type of certificate.
- name: changes
type: keyword
type: match_only_text
description: Changes done on fortimanager subtype.
- name: cli_act
type: keyword
Expand Down
2 changes: 1 addition & 1 deletion packages/fortinet_fortimanager/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -169,7 +169,7 @@ An example event for `log` looks as following:
| fortimanager.log.cause | Reason that causes HA status down. | keyword |
| fortimanager.log.cert.name | Name of certificate. | keyword |
| fortimanager.log.cert.type | Type of certificate. | keyword |
| fortimanager.log.changes | Changes done on fortimanager subtype. | keyword |
| fortimanager.log.changes | Changes done on fortimanager subtype. | match_only_text |
| fortimanager.log.cli_act | CLI command action. | keyword |
| fortimanager.log.cmd_from | CLI command from. | keyword |
| fortimanager.log.comment | The description of this policy package. | keyword |
Expand Down
2 changes: 1 addition & 1 deletion packages/fortinet_fortimanager/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: "3.0.3"
name: fortinet_fortimanager
title: Fortinet FortiManager Logs
version: "2.11.0"
version: "2.11.1"
description: Collect logs from Fortinet FortiManager instances with Elastic Agent.
type: integration
categories: ["security", "network", "firewall_security"]
Expand Down
5 changes: 5 additions & 0 deletions packages/m365_defender/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "2.8.1"
changes:
- description: Resolved ignore_malformed issues with fields.
type: bugfix
link: https://github.com/elastic/integrations/pull/9832
- version: "2.8.0"
changes:
- description: Set sensitive values as secret and fix incorrect mappings.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,6 @@ fields:
tags:
- preserve_original_event
- preserve_duplicate_custom_fields

dynamic_fields:
# This can be removed after ES 8.14 is the minimum version.
# Relates: https://github.com/elastic/elasticsearch/pull/105689
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -476,7 +476,7 @@
type: keyword
description: The ID of the alert as it appears in the security provider product that generated the alert.
- name: recommended_actions
type: keyword
type: match_only_text
description: Recommended response and remediation actions to take in the event this alert was generated.
- name: resolved_datetime
type: date
Expand Down
2 changes: 1 addition & 1 deletion packages/m365_defender/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -1579,7 +1579,7 @@ An example event for `incident` looks as following:
| m365_defender.incident.alert.last_update_datetime | Time when the alert was last updated at Microsoft 365 Defender. | date |
| m365_defender.incident.alert.mitre_techniques | The attack techniques, as aligned with the MITRE ATT&CK framework. | keyword |
| m365_defender.incident.alert.provider_alert_id | The ID of the alert as it appears in the security provider product that generated the alert. | keyword |
| m365_defender.incident.alert.recommended_actions | Recommended response and remediation actions to take in the event this alert was generated. | keyword |
| m365_defender.incident.alert.recommended_actions | Recommended response and remediation actions to take in the event this alert was generated. | match_only_text |
| m365_defender.incident.alert.resolved_datetime | Time when the alert was resolved. | date |
| m365_defender.incident.alert.service_source | The service or product that created this alert. Possible values are: microsoftDefenderForEndpoint, microsoftDefenderForIdentity, microsoftCloudAppSecurity, microsoftDefenderForOffice365, microsoft365Defender, aadIdentityProtection, appGovernance, dataLossPrevention. | keyword |
| m365_defender.incident.alert.severity | Indicates the possible impact on assets. The higher the severity the bigger the impact. Typically higher severity items require the most immediate attention. Possible values are: unknown, informational, low, medium, high, unknownFutureValue. | keyword |
Expand Down
2 changes: 1 addition & 1 deletion packages/m365_defender/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: "3.0.2"
name: m365_defender
title: Microsoft M365 Defender
version: "2.8.0"
version: "2.8.1"
description: Collect logs from Microsoft M365 Defender with Elastic Agent.
categories:
- "security"
Expand Down
5 changes: 5 additions & 0 deletions packages/panw/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "3.25.1"
changes:
- description: Resolved ignore_malformed issues with fields.
type: bugfix
link: https://github.com/elastic/integrations/pull/9832
- version: "3.25.0"
changes:
- description: Add audit log parsing
Expand Down
2 changes: 1 addition & 1 deletion packages/panw/data_stream/panos/fields/fields.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@
type: keyword
description: Username of the Administrator performing the configuration.
- name: after_change_detail
type: keyword
type: match_only_text
description: This field is in custom logs only; it is not in the default format.It contains the full xpath after the configuration change.
- name: application
type: group
Expand Down
2 changes: 1 addition & 1 deletion packages/panw/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -366,7 +366,7 @@ An example event for `panos` looks as following:
| panw.panos.action_flags | A bit field indicating if the log was forwarded to Panorama. | keyword |
| panw.panos.action_source | Specifies whether the action taken to allow or block an application was defined in the application or in policy. The actions can be allow, deny, drop, reset- server, reset-client or reset-both for the session. | keyword |
| panw.panos.admin | Username of the Administrator performing the configuration. | keyword |
| panw.panos.after_change_detail | This field is in custom logs only; it is not in the default format.It contains the full xpath after the configuration change. | keyword |
| panw.panos.after_change_detail | This field is in custom logs only; it is not in the default format.It contains the full xpath after the configuration change. | match_only_text |
| panw.panos.application.category | The application category specified in the application configuration properties. Values are: business-systems, collaboration, general-internet, media, networking, saas. | keyword |
| panw.panos.application.characteristics | Comma-separated list of applicable characteristic of the application. | keyword |
| panw.panos.application.container | The parent application for an application. | keyword |
Expand Down
2 changes: 1 addition & 1 deletion packages/panw/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: panw
title: Palo Alto Next-Gen Firewall
version: "3.25.0"
version: "3.25.1"
description: Collect logs from Palo Alto next-gen firewalls with Elastic Agent.
type: integration
format_version: "3.0.3"
Expand Down
5 changes: 5 additions & 0 deletions packages/tanium/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.9.1"
changes:
- description: Resolved ignore_malformed issues with fields.
type: bugfix
link: https://github.com/elastic/integrations/pull/9832
- version: "1.9.0"
changes:
- description: Update manifest format version to v3.0.3.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,4 +3,4 @@ fields:
- preserve_original_event
- preserve_duplicate_custom_fields
numeric_keyword_fields:
- tanium.threat_response.other_parameters.log_details.payload_decoded.finding.whats.intel_intra_ids.id
- tanium.threat_response.other_parameters.log_details.payload_decoded.finding.whats.intel_intra_ids.id
Original file line number Diff line number Diff line change
Expand Up @@ -9,4 +9,4 @@ data_stream:
preserve_original_event: true
preserve_duplicate_custom_fields: true
numeric_keyword_fields:
- tanium.threat_response.other_parameters.log_details.payload_decoded.finding.whats.intel_intra_ids.id
- tanium.threat_response.other_parameters.log_details.payload_decoded.finding.whats.intel_intra_ids.id
Original file line number Diff line number Diff line change
Expand Up @@ -9,4 +9,4 @@ data_stream:
preserve_original_event: true
preserve_duplicate_custom_fields: true
numeric_keyword_fields:
- tanium.threat_response.other_parameters.log_details.payload_decoded.finding.whats.intel_intra_ids.id
- tanium.threat_response.other_parameters.log_details.payload_decoded.finding.whats.intel_intra_ids.id
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@
type: group
fields:
- name: original
type: keyword
type: match_only_text
- name: log_details
type: group
fields:
Expand All @@ -46,7 +46,7 @@
type: keyword
description: Type of threat.
- name: payload
type: keyword
type: match_only_text
description: Decoded payload data.
- name: payload_decoded
type: group
Expand Down
4 changes: 2 additions & 2 deletions packages/tanium/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -985,7 +985,7 @@ An example event for `threat_response` looks as following:
| tanium.threat_response.event.name | Event name of the threat response. | keyword |
| tanium.threat_response.id | Threat response id. | keyword |
| tanium.threat_response.other_parameters.log_details.name | Name of threat. | keyword |
| tanium.threat_response.other_parameters.log_details.payload | Decoded payload data. | keyword |
| tanium.threat_response.other_parameters.log_details.payload | Decoded payload data. | match_only_text |
| tanium.threat_response.other_parameters.log_details.payload_decoded.config_id | Config id. | keyword |
| tanium.threat_response.other_parameters.log_details.payload_decoded.config_rev_id | Config rev.iD. | keyword |
| tanium.threat_response.other_parameters.log_details.payload_decoded.finding.domain | Finding domain. | keyword |
Expand Down Expand Up @@ -1099,7 +1099,7 @@ An example event for `threat_response` looks as following:
| tanium.threat_response.other_parameters.log_details.payload_decoded.match.version | Finding version. | version |
| tanium.threat_response.other_parameters.log_details.source | Source of threat. | keyword |
| tanium.threat_response.other_parameters.log_details.type | Type of threat. | keyword |
| tanium.threat_response.other_parameters.original | | keyword |
| tanium.threat_response.other_parameters.original | | match_only_text |
| tanium.threat_response.priority | Priority of the threat response. | keyword |
| tanium.threat_response.revision | Revision of the threat response. | keyword |
| tanium.threat_response.row_id | Row id for the threat response. | keyword |
Expand Down
2 changes: 1 addition & 1 deletion packages/tanium/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: "3.0.3"
name: tanium
title: Tanium
version: "1.9.0"
version: "1.9.1"
description: This Elastic integration collects logs from Tanium with Elastic Agent.
type: integration
categories:
Expand Down
5 changes: 5 additions & 0 deletions packages/tenable_io/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "3.0.1"
changes:
- description: Resolved ignore_malformed issues with fields.
type: bugfix
link: https://github.com/elastic/integrations/pull/9832
- version: "3.0.0"
changes:
- description: Changed data collection input type of all the data streams from HTTPJSON to CEL.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,6 @@
name: vulnerability.category
- external: ecs
name: vulnerability.classification
- external: ecs
name: vulnerability.description
- external: ecs
name: vulnerability.enumeration
- external: ecs
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -224,8 +224,8 @@
type: keyword
description: The name of the exploit in the D2 Elliot Web Exploitation framework.
- name: description
type: keyword
description: Full text description of the vulnerability.
type: text
Comment thread
ShourieG marked this conversation as resolved.
description: Full text description of the vulnerability plugin.
- name: exploit_available
type: boolean
description: A value specifying whether a public exploit exists for the vulnerability.
Expand Down Expand Up @@ -450,3 +450,9 @@
- name: state
type: keyword
description: "The state of the vulnerability as determined by the Tenable Vulnerability Management state service. Possible values include: open, reopen and fixed."
- name: vulnerability
type: group
fields:
- name: description
type: text
description: The description of the vulnerability.
Comment thread
ShourieG marked this conversation as resolved.
5 changes: 2 additions & 3 deletions packages/tenable_io/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -1010,7 +1010,7 @@ An example event for `vulnerability` looks as following:
| tenable_io.vulnerability.plugin.cvss3.vector.scope | | keyword |
| tenable_io.vulnerability.plugin.cvss3.vector.user_interaction | | keyword |
| tenable_io.vulnerability.plugin.d2_elliot_name | The name of the exploit in the D2 Elliot Web Exploitation framework. | keyword |
| tenable_io.vulnerability.plugin.description | Full text description of the vulnerability. | keyword |
| tenable_io.vulnerability.plugin.description | Full text description of the vulnerability plugin. | text |
| tenable_io.vulnerability.plugin.exploit_available | A value specifying whether a public exploit exists for the vulnerability. | boolean |
| tenable_io.vulnerability.plugin.exploit_framework.canvas | A value specifying whether an exploit exists in the Immunity CANVAS framework. | boolean |
| tenable_io.vulnerability.plugin.exploit_framework.core | A value specifying whether an exploit exists in the CORE Impact framework. | boolean |
Expand Down Expand Up @@ -1078,8 +1078,7 @@ An example event for `vulnerability` looks as following:
| tenable_io.vulnerability.state | The state of the vulnerability as determined by the Tenable Vulnerability Management state service. Possible values include: open, reopen and fixed. | keyword |
| vulnerability.category | The type of system or architecture that the vulnerability affects. These may be platform-specific (for example, Debian or SUSE) or general (for example, Database or Firewall). For example (https://qualysguard.qualys.com/qwebhelp/fo_portal/knowledgebase/vulnerability_categories.htm[Qualys vulnerability categories]) This field must be an array. | keyword |
| vulnerability.classification | The classification of the vulnerability scoring system. For example (https://www.first.org/cvss/) | keyword |
| vulnerability.description | The description of the vulnerability that provides additional context of the vulnerability. For example (https://cve.mitre.org/about/faqs.html#cve_entry_descriptions_created[Common Vulnerabilities and Exposure CVE description]) | keyword |
| vulnerability.description.text | Multi-field of `vulnerability.description`. | match_only_text |
| vulnerability.description | The description of the vulnerability. | text |
| vulnerability.enumeration | The type of identifier used for this vulnerability. For example (https://cve.mitre.org/about/) | keyword |
| vulnerability.id | The identification (ID) is the number portion of a vulnerability entry. It includes a unique identification number for the vulnerability. For example (https://cve.mitre.org/about/faqs.html#what_is_cve_id)[Common Vulnerabilities and Exposure CVE ID] | keyword |
| vulnerability.reference | A resource that provides additional information, context, and mitigations for the identified vulnerability. | keyword |
Expand Down
2 changes: 1 addition & 1 deletion packages/tenable_io/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: "3.0.2"
name: tenable_io
title: Tenable Vulnerability Management
version: "3.0.0"
version: "3.0.1"
description: Collect logs from Tenable Vulnerability Management with Elastic Agent.
type: integration
categories:
Expand Down
5 changes: 5 additions & 0 deletions packages/ti_threatconnect/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "0.5.1"
changes:
- description: Resolved ignore_malformed issues with fields.
type: bugfix
link: https://github.com/elastic/integrations/pull/9832
- version: "0.5.0"
changes:
- description: Add error handling to API requests.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -569,7 +569,7 @@
type: group
fields:
- name: description
type: keyword
type: text
description: The Tags description.
- name: id
type: keyword
Expand Down
2 changes: 1 addition & 1 deletion packages/ti_threatconnect/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -520,7 +520,7 @@ An example event for `indicator` looks as following:
| threat_connect.indicator.source | The Indicators source. | keyword |
| threat_connect.indicator.subject | The subject line of the email associated with the Email Subject Indicator. | keyword |
| threat_connect.indicator.summary | Summary or description of the indicator. | keyword |
| threat_connect.indicator.tags.data.description | The Tags description. | keyword |
| threat_connect.indicator.tags.data.description | The Tags description. | text |
| threat_connect.indicator.tags.data.id | Unique Identifier of tag. | keyword |
| threat_connect.indicator.tags.data.last_used | Date and time when tag was last used. | date |
| threat_connect.indicator.tags.data.name | Name of tag. | keyword |
Expand Down
2 changes: 1 addition & 1 deletion packages/ti_threatconnect/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: 3.0.3
name: ti_threatconnect
title: ThreatConnect
version: 0.5.0
version: 0.5.1
description: Collect logs from ThreatConnect with Elastic Agent.
type: integration
categories:
Expand Down