[windows] AppLocker - Add more ECS fields, remove beta flag, add dashboard#7229
[windows] AppLocker - Add more ECS fields, remove beta flag, add dashboard#7229andrewkroh merged 33 commits intoelastic:mainfrom nicpenning:applocker_exe_and_dll_pipeline_and_dashboard_ga
Conversation
|
Any chance I can request @efd6 to assist in reviewing? He did a good job on the initial data stream creation for this Integration and this PR is a continuation of that. |
packages/windows/data_stream/applocker_exe_and_dll/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
|
Please let me know what you think about the new fields. In the meanwhile, this should be good to test. |
|
Just checking in on this 😀 |
andrewkroh
left a comment
There was a problem hiding this comment.
I think this data fits perfectly with the descriptions for these fields. I thinking we could use these fields instead of winlog.fqbn. WDYT?
- file.pe.file_version
- file.pe.original_file_name
- file.pe.product
...m/applocker_exe_and_dll/_dev/test/pipeline/test-events-applocker-exe-8003.json-expected.json
Show resolved
Hide resolved
...m/applocker_exe_and_dll/_dev/test/pipeline/test-events-applocker-exe-8003.json-expected.json
Outdated
Show resolved
Hide resolved
...m/applocker_exe_and_dll/_dev/test/pipeline/test-events-applocker-exe-8003.json-expected.json
Outdated
Show resolved
Hide resolved
...m/applocker_exe_and_dll/_dev/test/pipeline/test-events-applocker-exe-8003.json-expected.json
Outdated
Show resolved
Hide resolved
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
Pushed these changes. |
|
/test |
🌐 Coverage report
|
|
Thank you, Andrew! Next up, AppLocker MSI/Script data stream 😀 |
packages/windows/data_stream/applocker_exe_and_dll/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
…ch/ingest_pipeline/default.yml Co-authored-by: Andrew Kroh <andrew.kroh@elastic.co>
|
/test |
|
Package windows - 1.29.0 containing this change is available at https://epr.elastic.co/search?package=windows |
What does this PR do?
This PR extends the initial applocker data stream for exes and dlls by adding some more ECS fields, cleanup of uneeded processors, adds a dashboard and removes the [beta] flag.
Checklist
changelog.ymlfile.