Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

all: migrate ssi packages to ecs@mappings #10135

Merged
merged 121 commits into from
Jun 21, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
121 commits
Select commit Hold shift + click to select a range
9b151d7
[1password] - Updated fields definitions
efd6 Jun 20, 2024
447cd63
[akamai] - Updated fields definitions
efd6 Jun 20, 2024
1c018cf
[amazon_security_lake] - removed ecs import_mappings
efd6 Jun 20, 2024
731f66e
[atlassian_bitbucket] - Updated fields definitions
efd6 Jun 20, 2024
2fe7ad4
[atlassian_confluence] - Updated fields definitions
efd6 Jun 20, 2024
7bc15c5
[atlassian_jira] - Updated fields definitions
efd6 Jun 20, 2024
794fc08
[auth0] - Updated fields definitions
efd6 Jun 20, 2024
a549f10
[aws_bedrock] - Updated fields definitions
efd6 Jun 20, 2024
3a1173a
[azure_blob_storage] - removed ecs import_mappings
efd6 Jun 20, 2024
86879b9
[azure_frontdoor] - Updated fields definitions
efd6 Jun 20, 2024
e86d8a3
[azure_network_watcher_nsg] - removed ecs import_mappings
efd6 Jun 20, 2024
51a1920
[azure_network_watcher_vnet] - removed ecs import_mappings
efd6 Jun 20, 2024
95d1079
[barracuda] - Updated fields definitions
efd6 Jun 20, 2024
e200836
[barracuda_cloudgen_firewall] - Updated fields definitions
efd6 Jun 20, 2024
5d26f72
[bbot] - removed ecs import_mappings
efd6 Jun 20, 2024
362d282
[bitdefender] - Updated fields definitions
efd6 Jun 20, 2024
551089c
[bitwarden] - removed ecs import_mappings
efd6 Jun 20, 2024
7e50996
[box_events] - Updated fields definitions
efd6 Jun 20, 2024
a9b5a9c
[carbon_black_cloud] - Updated fields definitions
efd6 Jun 20, 2024
70de6ca
[carbonblack_edr] - Updated fields definitions
efd6 Jun 20, 2024
318ee01
[cel] - Updated fields definitions
efd6 Jun 20, 2024
3e0aa34
[cisa_kevs] - Updated fields definitions
efd6 Jun 20, 2024
d18fee2
[cisco_duo] - Updated fields definitions
efd6 Jun 20, 2024
bea8c1d
[cisco_meraki] - Updated fields definitions
efd6 Jun 20, 2024
754a971
[cisco_secure_endpoint] - Updated fields definitions
efd6 Jun 20, 2024
4589477
[cisco_umbrella] - Updated fields definitions
efd6 Jun 20, 2024
7f68039
[cloudflare] - Updated fields definitions
efd6 Jun 20, 2024
2c385f3
[cloudflare_logpush] - Updated fields definitions
efd6 Jun 20, 2024
56a71ba
[cribl] - change to ECS version [email protected]
efd6 Jun 20, 2024
7404076
[crowdstrike] - removed ecs import_mappings
efd6 Jun 20, 2024
d2c3bc6
[cyberarkpas] - Updated fields definitions
efd6 Jun 20, 2024
c27b3a3
[cyberark_pta] - Updated fields definitions
efd6 Jun 20, 2024
616c9fd
[cybereason] - removed ecs import_mappings
efd6 Jun 20, 2024
406a770
[cylance] - Updated fields definitions
efd6 Jun 20, 2024
0cf0d66
[darktrace] - Updated fields definitions
efd6 Jun 20, 2024
4e5db15
[entityanalytics_ad] - removed ecs import_mappings
efd6 Jun 20, 2024
d023a59
[entityanalytics_okta] - removed ecs import_mappings
efd6 Jun 20, 2024
dc8b131
[eset_protect] - Updated fields definitions
efd6 Jun 20, 2024
4cadbbe
[f5_bigip] - Updated fields definitions
efd6 Jun 20, 2024
e7c2b0d
[fireeye] - Updated fields definitions
efd6 Jun 20, 2024
fae0200
[forcepoint_web] - Updated fields definitions
efd6 Jun 20, 2024
6de5352
[forgerock] - Updated fields definitions
efd6 Jun 20, 2024
e48deab
[gcp_pubsub] - Updated fields definitions
efd6 Jun 20, 2024
75a8145
[github] - Updated fields definitions
efd6 Jun 20, 2024
ad230d8
[gitlab] - Updated fields definitions
efd6 Jun 20, 2024
f44a10c
[google_cloud_storage] - removed ecs import_mappings
efd6 Jun 20, 2024
5405033
[google_scc] - removed ecs import_mappings
efd6 Jun 20, 2024
668ebb4
[google_workspace] - removed ecs import_mappings
efd6 Jun 20, 2024
afa38a8
[http_endpoint] - Updated fields definitions
efd6 Jun 20, 2024
9ec2551
[httpjson] - Updated fields definitions
efd6 Jun 20, 2024
87d7248
[imperva_cloud_waf] - Updated fields definitions
efd6 Jun 20, 2024
aabe34a
[infoblox_bloxone_ddi] - Updated fields definitions
efd6 Jun 20, 2024
55e3148
[infoblox_nios] - Updated fields definitions
efd6 Jun 20, 2024
e7e19da
[jamf_compliance_reporter] - Updated fields definitions
efd6 Jun 20, 2024
d1cb76d
[jamf_protect] - Updated fields definitions
efd6 Jun 20, 2024
2de821d
[jumpcloud] - Updated fields definitions
efd6 Jun 20, 2024
e0c703d
[keycloak] - Updated fields definitions
efd6 Jun 20, 2024
026d900
[lastpass] - Updated fields definitions
efd6 Jun 20, 2024
bcc3812
[lumos] - Updated fields definitions
efd6 Jun 20, 2024
f2ca79b
[lyve_cloud] - Updated fields definitions
efd6 Jun 20, 2024
3700f8e
[m365_defender] - removed ecs import_mappings
efd6 Jun 20, 2024
402bbef
[mattermost] - Updated fields definitions
efd6 Jun 20, 2024
4bf6e53
[menlo] - Updated fields definitions
efd6 Jun 20, 2024
9a3922d
[microsoft_defender_cloud] - removed ecs import_mappings
efd6 Jun 20, 2024
cd5beb5
[microsoft_defender_endpoint] - Updated fields definitions
efd6 Jun 20, 2024
5ca9474
[microsoft_exchange_online_message_trace] - Updated fields definitions
efd6 Jun 20, 2024
9a99af1
[mimecast] - Updated fields definitions
efd6 Jun 20, 2024
e7694ca
[netskope] - Updated fields definitions
efd6 Jun 20, 2024
a9389db
[o365] - Updated fields definitions
efd6 Jun 20, 2024
9ebcf85
[okta] - Updated fields definitions
efd6 Jun 20, 2024
55ec115
[opencanary] - Updated fields definitions
efd6 Jun 20, 2024
43d0b20
[panw_cortex_xdr] - Updated fields definitions
efd6 Jun 20, 2024
4360e89
[ping_one] - Updated fields definitions
efd6 Jun 20, 2024
2101298
[pps] - Updated fields definitions
efd6 Jun 20, 2024
0ef94f0
[prisma_cloud] - removed ecs import_mappings
efd6 Jun 20, 2024
de98d92
[proofpoint_tap] - Updated fields definitions
efd6 Jun 20, 2024
7367e2c
[pulse_connect_secure] - Updated fields definitions
efd6 Jun 20, 2024
456dddc
[qualys_vmdr] - removed ecs import_mappings
efd6 Jun 20, 2024
11cf779
[rapid7_insightvm] - removed ecs import_mappings
efd6 Jun 20, 2024
c7b0a19
[santa] - Updated fields definitions
efd6 Jun 20, 2024
ea5802a
[sentinel_one] - Updated fields definitions
efd6 Jun 20, 2024
45d9564
[sentinel_one_cloud_funnel] - Updated fields definitions
efd6 Jun 20, 2024
a2379f4
[slack] - Updated fields definitions
efd6 Jun 20, 2024
1024904
[snyk] - Updated fields definitions
efd6 Jun 20, 2024
55519bb
[sophos_central] - removed ecs import_mappings
efd6 Jun 20, 2024
80d9c8e
[symantec_edr_cloud] - removed ecs import_mappings
efd6 Jun 20, 2024
c4a8202
[symantec_endpoint] - Updated fields definitions
efd6 Jun 20, 2024
733965e
[symantec_endpoint_security] - removed ecs import_mappings
efd6 Jun 20, 2024
56c427e
[tanium] - removed ecs import_mappings
efd6 Jun 20, 2024
d95e665
[tenable_io] - Updated fields definitions
efd6 Jun 20, 2024
5c469a2
[tenable_sc] - Updated fields definitions
efd6 Jun 20, 2024
e0e2387
[thycotic_ss] - Updated fields definitions
efd6 Jun 20, 2024
5819d1e
[ti_abusech] - Updated fields definitions
efd6 Jun 20, 2024
1e4184c
[ti_anomali] - Updated fields definitions
efd6 Jun 20, 2024
33d13c2
[ti_cif3] - Updated fields definitions
efd6 Jun 20, 2024
60ef8aa
[ti_crowdstrike] - Updated fields definitions
efd6 Jun 20, 2024
fa4ac20
[ti_cybersixgill] - Updated fields definitions
efd6 Jun 20, 2024
8aa2bc4
[ti_eclecticiq] - change to ECS version [email protected]
efd6 Jun 20, 2024
81e93de
[ti_eset] - Updated fields definitions
efd6 Jun 20, 2024
e2cb6d9
[ti_maltiverse] - Updated fields definitions
efd6 Jun 20, 2024
0573986
[ti_mandiant_advantage] - change to ECS version [email protected]
efd6 Jun 20, 2024
531d0dd
[ti_misp] - Updated fields definitions
efd6 Jun 20, 2024
6ebf32f
[tines] - Updated fields definitions
efd6 Jun 20, 2024
8b8b79a
[ti_opencti] - removed ecs import_mappings
efd6 Jun 20, 2024
5e7cb60
[ti_otx] - Updated fields definitions
efd6 Jun 20, 2024
6bb531a
[ti_rapid7_threat_command] - Updated fields definitions
efd6 Jun 20, 2024
405121a
[ti_recordedfuture] - Updated fields definitions
efd6 Jun 20, 2024
354598a
[ti_threatconnect] - removed ecs import_mappings
efd6 Jun 20, 2024
810f753
[ti_threatq] - Updated fields definitions
efd6 Jun 20, 2024
3de5621
[ti_util] - change to kibana constraint to ^8.13.0
efd6 Jun 20, 2024
0b6a37e
[trellix_edr_cloud] - removed ecs import_mappings
efd6 Jun 20, 2024
f1d94b8
[trellix_epo_cloud] - removed ecs import_mappings
efd6 Jun 20, 2024
3b1f987
[trendmicro] - removed ecs import_mappings
efd6 Jun 20, 2024
68147fa
[trend_micro_vision_one] - Updated fields definitions
efd6 Jun 20, 2024
dcd1f9c
[vectra_detect] - removed ecs import_mappings
efd6 Jun 20, 2024
cf76144
[wiz] - removed ecs import_mappings
efd6 Jun 20, 2024
aa97408
[zerofox] - Updated fields definitions
efd6 Jun 20, 2024
d58c31d
[zeronetworks] - Updated fields definitions
efd6 Jun 20, 2024
3e6b2ac
[zoom] - Updated fields definitions
efd6 Jun 20, 2024
3f1e14f
[zscaler_zia] - removed ecs import_mappings
efd6 Jun 20, 2024
fa913e1
[zscaler_zpa] - removed ecs import_mappings
efd6 Jun 20, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
5 changes: 5 additions & 0 deletions packages/1password/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.29.0"
changes:
- description: Update the kibana constraint to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template.
type: enhancement
link: https://github.com/elastic/integrations/pull/10135
- version: "1.28.0"
changes:
- description: Improve handling of empty responses.
Expand Down
44 changes: 0 additions & 44 deletions packages/1password/data_stream/audit_events/fields/ecs.yml

This file was deleted.

48 changes: 0 additions & 48 deletions packages/1password/data_stream/item_usages/fields/ecs.yml

This file was deleted.

50 changes: 0 additions & 50 deletions packages/1password/data_stream/signin_attempts/fields/ecs.yml

This file was deleted.

79 changes: 0 additions & 79 deletions packages/1password/docs/README.md

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions packages/1password/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
format_version: "3.0.2"
name: 1password
title: "1Password"
version: "1.28.0"
version: "1.29.0"
description: Collect logs from 1Password with Elastic Agent.
type: integration
categories:
- security
- credential_management
conditions:
kibana:
version: ^8.12.0
version: "^8.13.0"
screenshots:
- src: /img/1password-signinattempts-screenshot.png
title: Sign-in attempts
Expand Down
5 changes: 5 additions & 0 deletions packages/akamai/changelog.yml
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

__

Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "2.24.0"
changes:
- description: Update the kibana constraint to ^8.13.0. Modified the field definitions to remove ECS fields made redundant by the ecs@mappings component template.
type: enhancement
link: https://github.com/elastic/integrations/pull/10135
- version: "2.23.2"
changes:
- description: Handle HTTP headers without values.
Expand Down
93 changes: 1 addition & 92 deletions packages/akamai/data_stream/siem/fields/agent.yml
Original file line number Diff line number Diff line change
@@ -1,100 +1,9 @@
- name: host
title: Host
group: 2
description: 'A host is defined as a general computing instance.

ECS host.* fields should be populated with details about the host on which the event happened, or from which the measurement was taken. Host types include hardware, virtual machines, Docker containers, and Kubernetes nodes.'
description: 'A host is defined as a general computing instance. ECS host.* fields should be populated with details about the host on which the event happened, or from which the measurement was taken. Host types include hardware, virtual machines, Docker containers, and Kubernetes nodes.'
type: group
fields:
- name: architecture
level: core
type: keyword
ignore_above: 1024
description: Operating system architecture.
example: x86_64
- name: domain
level: extended
type: keyword
ignore_above: 1024
description: 'Name of the domain of which the host is a member.

For example, on Windows this could be the host''s Active Directory domain or NetBIOS domain name. For Linux this could be the domain of the host''s LDAP provider.'
example: CONTOSO
default_field: false
- name: hostname
level: core
type: keyword
ignore_above: 1024
description: 'Hostname of the host.

It normally contains what the `hostname` command returns on the host machine.'
- name: id
level: core
type: keyword
ignore_above: 1024
description: 'Unique host id.

As hostname is not always unique, use values that are meaningful in your environment.

Example: The current usage of `beat.name`.'
- name: ip
level: core
type: ip
description: Host ip addresses.
- name: mac
level: core
type: keyword
ignore_above: 1024
description: Host mac addresses.
- name: name
level: core
type: keyword
ignore_above: 1024
description: 'Name of the host.

It can contain what `hostname` returns on Unix systems, the fully qualified domain name, or a name specified by the user. The sender decides which value to use.'
- name: os.family
level: extended
type: keyword
ignore_above: 1024
description: OS family (such as redhat, debian, freebsd, windows).
example: debian
- name: os.kernel
level: extended
type: keyword
ignore_above: 1024
description: Operating system kernel version as a raw string.
example: 4.4.0-112-generic
- name: os.name
level: extended
type: keyword
ignore_above: 1024
multi_fields:
- name: text
type: text
norms: false
default_field: false
description: Operating system name, without the version.
example: Mac OS X
- name: os.platform
level: extended
type: keyword
ignore_above: 1024
description: Operating system platform (such centos, ubuntu, windows).
example: darwin
- name: os.version
level: extended
type: keyword
ignore_above: 1024
description: Operating system version as a raw string.
example: 10.14.1
- name: type
level: core
type: keyword
ignore_above: 1024
description: 'Type of host.

For Cloud providers this can be the machine type like `t2.medium`. If vm, this could be the container, for example, or other information meaningful in your environment.'
- name: containerized
type: boolean
description: >
Expand Down
3 changes: 0 additions & 3 deletions packages/akamai/data_stream/siem/fields/beats.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,3 @@
- name: log.offset
type: long
description: Offset of the entry in the log file.
- name: log.file.path
type: keyword
description: Path to the log file.
Loading