The majority of our security integrations are currently experimental and our goal is to move these integrations towards GA in 7.14 to ensure full support as users adopt them in production environments.
Priority Order (based on Fleet telemetry)
- [ ] Cisco
- [x] All edge processing in ingest pipelines (missing RSA) #1073
- [x] event.original is optional #1073
- [ ] Bump version #1220
Other packages (non RSA) that meet all requirements to GA
Partially (not all data streams) RSA packages
Non RSA packages
- CEF
- Checkpoint
- Crowdstrike
- Cyberarkpas
- GCP
- Iptables
- Santa
- Google Workspace
- Osquery
Requirements for moving a package to GA:
- Any package with httpjson input requires:
- All packages require:
The majority of our security integrations are currently experimental and our goal is to move these integrations towards GA in 7.14 to ensure full support as users adopt them in production environments.
Priority Order (based on Fleet telemetry)
event.originalis optionalevent.originalis optional [auditd] Move edge to ingest pipeline and make event.original optional #989event.originalis optional [suricata] Make event.original optional #991event.originalis optional [zeek] Make event.original optional #992- [ ]not applyevent.originalis optionalevent.originalis optional [O365] updating o365 ECS version and adding event.original options #1117- [ ] Cisco- [x] All edge processing in ingest pipelines (missing RSA) #1073- [x]event.originalis optional #1073- [ ] Bump version #1220event.originalis optional [panw] Make event.original optional #1007event.originalis optional [okta] Make event.original optional #1009event.originalis optional [fortinet] Make event.original optional in fortinet #1075Other packages (non RSA) that meet all requirements to GA
Partially (not all data streams) RSA packages
Non RSA packages
Requirements for moving a package to GA:
Persistent storage for registry data in Hosted Elastic Agent https://github.com/elastic/ingest-dev/issues/1032