Cyberark Privileged Access Security module#24803
Conversation
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
adriansr
left a comment
There was a problem hiding this comment.
Notes to reviewers.
Don't be overwhelmed by the size of the PR. Most of it are sample logs that I plan to reduce.
There was a problem hiding this comment.
This file is necessary to configure the Vault, but it's not used by the module. Added it here so that it's under version control. We need to see how to distribute it.
There was a problem hiding this comment.
TODO: Most of these comments can be moved to a description field.
There was a problem hiding this comment.
Note to reviewers: Please review these mappings
💚 Build Succeeded
Expand to view the summary
Build stats
Test stats 🧪
Trends 🧪💚 Flaky test reportTests succeeded. Expand to view the summary
Test stats 🧪
|
727eb7d to
2a461e5
Compare
|
/test |
andrewkroh
left a comment
There was a problem hiding this comment.
Thanks documenting the pipeline so well!
There was a problem hiding this comment.
Is this for adding network_direction? We do have that available in Ingest Node too now.
There was a problem hiding this comment.
Thanks, I added the ingest node processor. However, I don't see a way for the user to pass custom internal networks in a way that's compatible with packages. Any ideas?
Technically it should escape all control characters (0-0x1f) but I can't find a way to do that in XSLT v1.0. Only TAB, CR and LF can be represented.
This PR adds a new module, cyberarkpas, to ingest Privileged Access Security audit logs from Vault via syslog. (cherry picked from commit 2d51864)
…-github-pr-comment-template * upstream/master: [Ingest Manager] Keep http and logging config during enroll (elastic#25132) Refactor kubernetes autodiscover to avoid skipping short-living pods (elastic#24742) [libbeat] New decode xml wineventlog processor (elastic#25115) Add svc to agent k8s clusterRole (elastic#25146) Add awsfargate module to collect container logs from Amazon ECS on Fargate (elastic#25041) [Filebeat][Cisco ASA] log enhancement and performance (elastic#24744) Watch kubernetes namespaces for autodiscover metadata for pods (elastic#25117) Cyberark Privileged Access Security module (elastic#24803) [Elastic Agent] Log the container command output with LOGS_PATH (elastic#25150) Fix for tests after `device...` field has been removed (elastic#25141) [Ingest Manager] Restart process on output change (elastic#24907) Set --insecure in container when FLEET_SERVER_ENABLE and FLEET_INSECURE set. (elastic#25137) [filebeat] Update documentation / changelog / beta warnings for the syslog input (elastic#25047) Add support for ignore_inactive in filestream input (elastic#25036) Fix bug with annotations dedot config on k8s not used (elastic#25111)
Adds a new package, cyberarkpas, for Cyberark Privileged Access Security audit logs (from elastic/beats#24803)
This PR adds a new module,
cyberarkpas, to ingest Privileged Access Security audit logs from Vault via syslog.Checklist
CHANGELOG.next.asciidocorCHANGELOG-developer.next.asciidoc.Author's Checklist
How to test this PR locally
Related issues
Use cases
Screenshots
Dashboard:
Logs