[system] Add Windows Firewall events#6534
Conversation
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
efd6
left a comment
There was a problem hiding this comment.
What is the source of the events?
packages/system/data_stream/security/elasticsearch/ingest_pipeline/standard.yml
Outdated
Show resolved
Hide resolved
packages/system/data_stream/security/elasticsearch/ingest_pipeline/standard.yml
Outdated
Show resolved
Hide resolved
|
/test |
🌐 Coverage report
|
Events from the system.security dataset from one of our clusters where these audits have been enabled by GPO. |
|
Thanks. We'll note that as "User-provided test cases" in the commit message. |
|
/test |
|
@efd6 Anything I need to do about BuildKite failing? I have not seen that one fail before. |
|
It looks like it's not properly configured yet, so no. |
|
Resolved conflicts. Ready to test. |
|
/test |
|
I am ready to fix conflicts if #6528 is pulled before this one :) |
|
/test |
|
Any updates? |
|
/test |
|
Ready for test |
|
/test |
|
@efd6 Resolved conflicts again. |
|
@LaZyDK I'm afraid it's not under my control. We don't own this package. |
|
/test |
|
@SubhrataK as the codeowners, could someone from your team please review/merge this PR. It's adding Windows Firewall Events to the Windows Security Events datastream in the System package. |
|
/test |
|
Resolved conflicts and ran tests again. Ready to merge after CI tests. |
|
@SubhrataK or @ishleenk17 I resolved conflicts again. Waiting for a merge. |
Will merge it once the CI passes. Thanks |
|
Package system - 1.38.0 containing this change is available at https://epr.elastic.co/search?package=system |
|
I am of the opinion this needs to go to the Windows integration. What are your guys thoughts? My plan was to introduce this data stream after we can get through AppLocker, but @LaZyDK beat me to it 😃 Update: Disregard, I suppose this is due to the Security channel being in the System channel anyways. I will put my thoughts together in an issue for my reasons that System, Security and Application should also live in the Windows integration for simplifying managing windows event logs. Thanks for the PR here! |
|
Also, thanks for fixing that improper PR link, you da man! |
What does this PR do?
Add Windows Firewall connection and packet drop events.
Checklist
changelog.ymlfile.Related issues