Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
57 commits
Select commit Hold shift + click to select a range
fbfb672
Update opencanary
alaudazzi May 27, 2025
2202cdf
Update ping_federate
alaudazzi May 27, 2025
d1568af
Update pps
alaudazzi May 28, 2025
b4fa015
Update prisma_access
alaudazzi May 30, 2025
bc352c0
Update prisma_cloud
alaudazzi May 30, 2025
6665e84
Update proofpoint-itm
alaudazzi Jun 2, 2025
92fd7c6
Update proofpoint_on_demand
alaudazzi Jun 2, 2025
76121e1
Update qualys_vmdr
alaudazzi Jun 2, 2025
2ccf02f
Update qualys and sentinel_one_cloud_funnel
alaudazzi Jun 2, 2025
e50178f
Update servicenow
alaudazzi Jun 2, 2025
bf50f10
Update splunk
alaudazzi Jun 4, 2025
579ab1e
Update spycloud
alaudazzi Jun 4, 2025
305e92c
Update sublime_security
alaudazzi Jun 4, 2025
6f94f0f
Update symantec_endpoint_security
alaudazzi Jun 4, 2025
6436f88
Update teleport
alaudazzi Jun 4, 2025
7800852
Update tenable_io
alaudazzi Jun 4, 2025
ab8c72c
Update ti_crowdstrike
alaudazzi Jun 4, 2025
a8613aa
Update ti_eset
alaudazzi Jun 4, 2025
d865667
Update ti_rapid7_threat_command
alaudazzi Jun 4, 2025
ec144cf
Update ti_threatconnect
alaudazzi Jun 5, 2025
70d6366
Update ti_threatq
alaudazzi Jun 5, 2025
0f96e9d
Update trellix_edr_cloud
alaudazzi Jun 5, 2025
d71a6a1
Update trendmicro
alaudazzi Jun 5, 2025
b0008ad
Update wiz
alaudazzi Jun 5, 2025
2463cfd
Update zscaler_zia
alaudazzi Jun 5, 2025
ab749df
Merge branch 'main' into remove-duplicated-install-instruct
alaudazzi Jun 5, 2025
2a8084d
Update zscaler_zia
alaudazzi Jun 5, 2025
8a0bd56
Merge branch 'remove-duplicated-install-instruct' of github.com:elast…
alaudazzi Jun 5, 2025
b6da6aa
Update manifest and changelog
alaudazzi Jun 5, 2025
8ada671
Update packages/zscaler_zia/_dev/build/docs/README.md
alaudazzi Jun 16, 2025
aa48b6d
Update packages/opencanary/_dev/build/docs/README.md
alaudazzi Jun 16, 2025
bf4b3ff
Update packages/qualys_vmdr/_dev/build/docs/README.md
alaudazzi Jun 16, 2025
136cb21
Update packages/ti_threatconnect/_dev/build/docs/README.md
alaudazzi Jun 16, 2025
14c207a
Update packages/wiz/_dev/build/docs/README.md
alaudazzi Jun 16, 2025
a33fbd0
Update packages/splunk/_dev/build/docs/README.md
alaudazzi Jun 16, 2025
e44579b
Update packages/opencanary/docs/README.md
alaudazzi Jun 16, 2025
83540ef
Update packages/ti_threatq/_dev/build/docs/README.md
alaudazzi Jun 16, 2025
4e2526d
Update packages/opencanary/changelog.yml
alaudazzi Jun 16, 2025
aa40dde
Update packages/tenable_io/_dev/build/docs/README.md
alaudazzi Jun 16, 2025
c1fff96
Integrate reviewer comments
alaudazzi Jun 16, 2025
89f946d
Integrate reviewer comments
alaudazzi Jun 16, 2025
d79a561
Integrate reviewer comments
alaudazzi Jun 16, 2025
5220bb1
Merge branch 'main' into remove-duplicated-install-instruct
alaudazzi Jun 16, 2025
e4987c8
Remove dead URL
alaudazzi Jun 16, 2025
f842043
Update manifest for ping_federate
alaudazzi Jun 18, 2025
338e660
Update manifest for qualys_vmdr
alaudazzi Jun 18, 2025
b0dfd15
Update manifest for teleport
alaudazzi Jun 18, 2025
9f9413d
Update manifest for tenable_io
alaudazzi Jun 18, 2025
246bb8c
Merge branch 'master' into remove-duplicated-install-instruct
efd6 Jun 18, 2025
5ef3f12
Update README
shmsr Jun 18, 2025
e32561b
ti_threatconnect: update transform
efd6 Jun 18, 2025
6c0cce8
Merge branch 'main' into remove-duplicated-install-instruct
alaudazzi Jun 18, 2025
2178a88
Update manifest for sentinel_one_cloud_funnel
alaudazzi Jun 18, 2025
28b5e6a
Update packages/prisma_cloud/_dev/build/docs/README.md
alaudazzi Jun 18, 2025
7cfde08
Update packages/proofpoint_itm/_dev/build/docs/README.md
alaudazzi Jun 18, 2025
6d3f25f
run elastic-package for prisma_cloud
alaudazzi Jun 18, 2025
d412438
Run elastic-package for proofpoint_itm
alaudazzi Jun 18, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 8 additions & 28 deletions packages/opencanary/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,39 +6,19 @@ This integration is for [Thinkst OpenCanary](https://github.com/thinkst/opencana

The OpenCanary integration collects the following event types:

- **events**
`events`: Collects the OpenCanary logs.

## Requirements

Elastic Agent must be installed. For more details and installation instructions, please refer to the [Elastic Agent Installation Guide](https://www.elastic.co/guide/en/fleet/current/elastic-agent-installation.html).
Elastic Agent must be installed. For more details, check the Elastic Agent [installation instructions](docs-content://reference/fleet/install-elastic-agents.md).

### Installing and managing an Elastic Agent:
### Enable the integration in Elastic

There are several options for installing and managing Elastic Agent:

### Install a Fleet-managed Elastic Agent (recommended):

With this approach, you install Elastic Agent and use Fleet in Kibana to define, configure, and manage your agents in a central location. We recommend using Fleet management because it makes the management and upgrade of your agents considerably easier.

### Install Elastic Agent in standalone mode (advanced users):

With this approach, you install Elastic Agent and manually configure the agent locally on the system where it’s installed. You are responsible for managing and upgrading the agents. This approach is reserved for advanced users only.

### Install Elastic Agent in a containerized environment:

You can run Elastic Agent inside a container, either with Fleet Server or standalone. Docker images for all versions of Elastic Agent are available from the Elastic Docker registry, and we provide deployment manifests for running on Kubernetes.

Please note, there are minimum requirements for running Elastic Agent. For more information, refer to the [Elastic Agent Minimum Requirements](https://www.elastic.co/guide/en/fleet/current/elastic-agent-installation.html#elastic-agent-installation-minimum-requirements).


### Enabling the integration in Elastic:

1. In Kibana navigate to Management > Integrations.
2. In "Search for integrations" top bar, search for `OpenCanary`.
3. Select the "OpenCanary" integration from the search results.
4. Select "Add OpenCanary" to add the integration.
5. Add all the required integration configuration parameters.
6. Select "Save and continue" to save the integration.
1. In Kibana navigate to **Management** > **Integrations**.
2. In the search top bar, type **OpenCanary**.
3. Select the **OpenCanary** integration and add it.
4. Add all the required integration configuration parameters.
5. Save the integration.

## Logs

Expand Down
5 changes: 5 additions & 0 deletions packages/opencanary/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "0.6.0"
changes:
- description: Remove duplicated installation instructions from the documentation.
type: enhancement
link: https://github.com/elastic/integrations/pull/14014
- version: "0.5.0"
changes:
- description: Make password redaction available for basic subscription.
Expand Down
36 changes: 8 additions & 28 deletions packages/opencanary/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,39 +6,19 @@ This integration is for [Thinkst OpenCanary](https://github.com/thinkst/opencana

The OpenCanary integration collects the following event types:

- **events**
`events`: Collects the OpenCanary logs.

## Requirements

Elastic Agent must be installed. For more details and installation instructions, please refer to the [Elastic Agent Installation Guide](https://www.elastic.co/guide/en/fleet/current/elastic-agent-installation.html).
Elastic Agent must be installed. For more details, check the Elastic Agent [installation instructions](docs-content://reference/fleet/install-elastic-agents.md).

### Installing and managing an Elastic Agent:
### Enable the integration in Elastic

There are several options for installing and managing Elastic Agent:

### Install a Fleet-managed Elastic Agent (recommended):

With this approach, you install Elastic Agent and use Fleet in Kibana to define, configure, and manage your agents in a central location. We recommend using Fleet management because it makes the management and upgrade of your agents considerably easier.

### Install Elastic Agent in standalone mode (advanced users):

With this approach, you install Elastic Agent and manually configure the agent locally on the system where it’s installed. You are responsible for managing and upgrading the agents. This approach is reserved for advanced users only.

### Install Elastic Agent in a containerized environment:

You can run Elastic Agent inside a container, either with Fleet Server or standalone. Docker images for all versions of Elastic Agent are available from the Elastic Docker registry, and we provide deployment manifests for running on Kubernetes.

Please note, there are minimum requirements for running Elastic Agent. For more information, refer to the [Elastic Agent Minimum Requirements](https://www.elastic.co/guide/en/fleet/current/elastic-agent-installation.html#elastic-agent-installation-minimum-requirements).


### Enabling the integration in Elastic:

1. In Kibana navigate to Management > Integrations.
2. In "Search for integrations" top bar, search for `OpenCanary`.
3. Select the "OpenCanary" integration from the search results.
4. Select "Add OpenCanary" to add the integration.
5. Add all the required integration configuration parameters.
6. Select "Save and continue" to save the integration.
1. In Kibana navigate to **Management** > **Integrations**.
2. In the search top bar, type **OpenCanary**.
3. Select the **OpenCanary** integration and add it.
4. Add all the required integration configuration parameters.
5. Save the integration.

## Logs

Expand Down
2 changes: 1 addition & 1 deletion packages/opencanary/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: 3.1.3
name: opencanary
title: "OpenCanary"
version: "0.5.0"
version: "0.6.0"
description: "This integration collects and parses logs from OpenCanary honeypots."
type: integration
categories:
Expand Down
44 changes: 12 additions & 32 deletions packages/ping_federate/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,43 +37,23 @@ CEF:0|Ping Identity|PingFederate|6.4|AUTHN_SESSION_DELETED|AUTHN_SESSION_DELETED

## Requirements

- Elastic Agent must be installed.
- You can install only one Elastic Agent per host.
- Elastic Agent is required to stream data through the Filestream or TCP/UDP and ship the data to Elastic, where the events will then be processed via the integration's ingest pipelines.

### Installing and managing an Elastic Agent:

You have a few options for installing and managing an Elastic Agent:

### Install a Fleet-managed Elastic Agent (recommended):

With this approach, you install Elastic Agent and use Fleet in Kibana to define, configure, and manage your agents in a central location. We recommend using Fleet management because it makes the management and upgrade of your agents considerably easier.

### Install Elastic Agent in standalone mode (advanced users):

With this approach, you install Elastic Agent and manually configure the agent locally on the system where it’s installed. You are responsible for managing and upgrading the agents. This approach is reserved for advanced users only.

### Install Elastic Agent in a containerized environment:

You can run Elastic Agent inside a container, either with Fleet Server or standalone. Docker images for all versions of Elastic Agent are available from the Elastic Docker registry, and we provide deployment manifests for running on Kubernetes.

There are some minimum requirements for running Elastic Agent. For more information, refer to the Elastic Agent [installation guide](https://www.elastic.co/guide/en/fleet/current/elastic-agent-installation.html).
Elastic Agent must be installed. For more details, check the Elastic Agent [installation instructions](docs-content://reference/fleet/install-elastic-agents.md). You can install only one Elastic Agent per host.
Elastic Agent is required to stream data through the Filestream or TCP/UDP and ship the data to Elastic, where the events will then be processed via the integration's ingest pipelines.

## Setup

1. For step-by-step instructions on how to configure log files in PingFederate instance, see the [Log4j 2 logging service and configuration](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_log4j_2_loggin_service_and_config.html) guide.
2. To write the audit logs in cef format, see the [Writing audit log in CEF](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_writin_audit_log_cef.html) guide.
1. To configure log files in the PingFederate instance, check the [Log4j 2 logging service and configuration](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_log4j_2_loggin_service_and_config.html) guide.
2. To write the audit logs in CEF format, check the [Writing audit log in CEF](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_writin_audit_log_cef.html) guide.

### Enabling the integration in Elastic:
### Enable the integration in Elastic

1. In Kibana go to Management > Integrations.
2. In "Search for integrations" search bar, type PingFederate.
3. Click on the "PingFederate" integration from the search results.
4. Click on the "Add PingFederate" button to add the integration.
5. Select the toggle for the data stream for which you want to collect logs.
6. Enable the data collection mode from the following: Filestream, TCP, or UDP. (Admin logs are only supported through Filestream)
7. Add all the required configuration parameters, such as paths for the filestream or listen address and listen port for the TCP and UDP.
8. Click on "Save and Continue" to save the integration.
1. In Kibana go to **Management** > **Integrations**.
2. In the search top bar, type **PingFederate**.
3. Select the **PingFederate** integration and add it.
4. Select the toggle for the data stream for which you want to collect logs.
5. Enable the data collection mode: Filestream, TCP, or UDP. Admin logs are only supported through Filestream.
6. Add all the required configuration parameters, such as paths for the filestream or listen address and listen port for the TCP and UDP.
7. Save the integration.

## Logs Reference

Expand Down
5 changes: 5 additions & 0 deletions packages/ping_federate/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.0.2"
changes:
- description: Remove duplicated installation instructions from the documentation.
type: enhancement
link: https://github.com/elastic/integrations/pull/14014
- version: "1.0.1"
changes:
- description: Apply timezone setting correctly in the audit data stream.
Expand Down
44 changes: 12 additions & 32 deletions packages/ping_federate/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,43 +37,23 @@ CEF:0|Ping Identity|PingFederate|6.4|AUTHN_SESSION_DELETED|AUTHN_SESSION_DELETED

## Requirements

- Elastic Agent must be installed.
- You can install only one Elastic Agent per host.
- Elastic Agent is required to stream data through the Filestream or TCP/UDP and ship the data to Elastic, where the events will then be processed via the integration's ingest pipelines.

### Installing and managing an Elastic Agent:

You have a few options for installing and managing an Elastic Agent:

### Install a Fleet-managed Elastic Agent (recommended):

With this approach, you install Elastic Agent and use Fleet in Kibana to define, configure, and manage your agents in a central location. We recommend using Fleet management because it makes the management and upgrade of your agents considerably easier.

### Install Elastic Agent in standalone mode (advanced users):

With this approach, you install Elastic Agent and manually configure the agent locally on the system where it’s installed. You are responsible for managing and upgrading the agents. This approach is reserved for advanced users only.

### Install Elastic Agent in a containerized environment:

You can run Elastic Agent inside a container, either with Fleet Server or standalone. Docker images for all versions of Elastic Agent are available from the Elastic Docker registry, and we provide deployment manifests for running on Kubernetes.

There are some minimum requirements for running Elastic Agent. For more information, refer to the Elastic Agent [installation guide](https://www.elastic.co/guide/en/fleet/current/elastic-agent-installation.html).
Elastic Agent must be installed. For more details, check the Elastic Agent [installation instructions](docs-content://reference/fleet/install-elastic-agents.md). You can install only one Elastic Agent per host.
Elastic Agent is required to stream data through the Filestream or TCP/UDP and ship the data to Elastic, where the events will then be processed via the integration's ingest pipelines.

## Setup

1. For step-by-step instructions on how to configure log files in PingFederate instance, see the [Log4j 2 logging service and configuration](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_log4j_2_loggin_service_and_config.html) guide.
2. To write the audit logs in cef format, see the [Writing audit log in CEF](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_writin_audit_log_cef.html) guide.
1. To configure log files in the PingFederate instance, check the [Log4j 2 logging service and configuration](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_log4j_2_loggin_service_and_config.html) guide.
2. To write the audit logs in CEF format, check the [Writing audit log in CEF](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_writin_audit_log_cef.html) guide.

### Enabling the integration in Elastic:
### Enable the integration in Elastic

1. In Kibana go to Management > Integrations.
2. In "Search for integrations" search bar, type PingFederate.
3. Click on the "PingFederate" integration from the search results.
4. Click on the "Add PingFederate" button to add the integration.
5. Select the toggle for the data stream for which you want to collect logs.
6. Enable the data collection mode from the following: Filestream, TCP, or UDP. (Admin logs are only supported through Filestream)
7. Add all the required configuration parameters, such as paths for the filestream or listen address and listen port for the TCP and UDP.
8. Click on "Save and Continue" to save the integration.
1. In Kibana go to **Management** > **Integrations**.
2. In the search top bar, type **PingFederate**.
3. Select the **PingFederate** integration and add it.
4. Select the toggle for the data stream for which you want to collect logs.
5. Enable the data collection mode: Filestream, TCP, or UDP. Admin logs are only supported through Filestream.
6. Add all the required configuration parameters, such as paths for the filestream or listen address and listen port for the TCP and UDP.
7. Save the integration.

## Logs Reference

Expand Down
2 changes: 1 addition & 1 deletion packages/ping_federate/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: 3.2.1
name: ping_federate
title: PingFederate
version: "1.0.1"
version: "1.0.2"
description: Collect logs from PingFederate with Elastic Agent.
type: integration
categories:
Expand Down
62 changes: 21 additions & 41 deletions packages/pps/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,63 +4,43 @@ The Pleasant Password Server integration collects and parses DNS, DHCP, and Audi

## Data streams

The PPS integration collects the following event types:

- **log**

## Setup steps
1. Enable the integration with TCP/UDP input.
2. Log in to the PPS WebUI.
3. Configure the PPS to send messages to a Syslog server using the following steps.
1. From the Menu go to Logging -> Syslog Configuration
2. Set the Syslog Configuration to Enabled
3. Set Hostname to the Hostname of your Fleet Agent or Load Balancer
4. Set the Correct Port used in the Integration Configuration
5. Set UDP or TCP
6. Optionally set the Facility
The PPS integration collects the following event types: `log`.

## Compatibility

This module has been tested against `Pleasant Password Server Version 7.11.44.0 `.
It should however work with all versions.


## Requirements

Elastic Agent must be installed. For more details and installation instructions, please refer to the [Elastic Agent Installation Guide](https://www.elastic.co/guide/en/fleet/current/elastic-agent-installation.html).

### Installing and managing an Elastic Agent:

There are several options for installing and managing Elastic Agent:

### Install a Fleet-managed Elastic Agent (recommended):
Elastic Agent must be installed. For more details, check the Elastic Agent [installation instructions](docs-content://reference/fleet/install-elastic-agents.md).

With this approach, you install Elastic Agent and use Fleet in Kibana to define, configure, and manage your agents in a central location. We recommend using Fleet management because it makes the management and upgrade of your agents considerably easier.
## Setup

### Install Elastic Agent in standalone mode (advanced users):

With this approach, you install Elastic Agent and manually configure the agent locally on the system where it’s installed. You are responsible for managing and upgrading the agents. This approach is reserved for advanced users only.

### Install Elastic Agent in a containerized environment:

You can run Elastic Agent inside a container, either with Fleet Server or standalone. Docker images for all versions of Elastic Agent are available from the Elastic Docker registry, and we provide deployment manifests for running on Kubernetes.
1. Enable the integration with TCP/UDP input.
2. Log in to the PPS WebUI.
3. Configure the PPS to send messages to a Syslog server using the following steps.
1. From the menu go to **Logging** -> **Syslog Configuration**.
2. Set the Syslog Configuration to **Enabled**.
3. Set Hostname to the Hostname of your Fleet Agent or Load Balancer.
4. Set the Correct Port used in the Integration Configuration.
5. Set UDP or TCP.
6. Optionally set the Facility.

Please note, there are minimum requirements for running Elastic Agent. For more information, refer to the [Elastic Agent Minimum Requirements](https://www.elastic.co/guide/en/fleet/current/elastic-agent-installation.html#elastic-agent-installation-minimum-requirements).
### Enable the integration in Elastic

1. In Kibana navigate to **Management** > **Integrations**.
2. In the search top bar, type **Pleasant Password Server** or **PPS**.
3. Select the **Pleasant Password Server** integration and add it.
4. Add all the required integration configuration parameters.
5. Save the integration.

### Enabling the integration in Elastic:
## Log samples

1. In Kibana navigate to Management > Integrations.
2. In "Search for integrations" top bar, search for `Pleasant Password Server` or `PPS`.
3. Select the "Pleasant Password Server" integration from the search results.
4. Select "Add Pleasant Password Server" to add the integration.
5. Add all the required integration configuration parameters.
6. Select "Save and continue" to save the integration.
Below are the sample logs of the respective category.

## Log samples
Below are the samples logs of the respective category:
### Audit Logs

## Audit Logs:
```
<134>Jan 23 09:49:10 SRV-PPS-001 Pleasant Password Server:192.168.1.2 - user@name.test - - Success - Syslog Settings Changed - User <user@name.test> Syslogging setting updated changing the host from <localhost> to <127.0.0.1> changing the port fr 127.0.0.1 23/01 09:49:10.894
<134>Jan 23 11:32:57 SRV-PPS-001 Pleasant Password Server:192.168.1.2 - user@name.test - - Success - Password Fetched - User <user@name.test> fetched the password for <TOP/SECRET/PASSWORD> - test 127.0.0.1 23/01 11:32:57.857
Expand Down
5 changes: 5 additions & 0 deletions packages/pps/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.0.1"
changes:
- description: Remove duplicated installation instructions from the documentation.
type: enhancement
link: https://github.com/elastic/integrations/pull/14014
- version: "1.0.0"
changes:
- description: Release integration as GA.
Expand Down
Loading