Skip to content
This repository has been archived by the owner on Jan 27, 2023. It is now read-only.

Conversation

andrewkroh
Copy link
Member

@andrewkroh andrewkroh commented May 2, 2022

This PR promotes packages from snapshot to production.

Promoted packages:

  • 1password-1.3.0: c1ecdc1be71c2ca8
  • akamai-0.2.0: 91d7bd7fe2318552
  • atlassian_bitbucket-1.2.1: a376c903752f760b
  • atlassian_confluence-1.3.0: 7a783693bd0a9d83
  • atlassian_jira-1.2.0: 507bed66436283f1
  • auditd-2.2.0: 7f89dad854e55acc
  • barracuda-0.9.0: 4c9a1161f6b52dc7
  • bluecoat-0.8.0: 932b1c81b7fb1c7c
  • carbon_black_cloud-0.1.2: 02057fddc82975a2
  • carbonblack_edr-1.2.0: a01d621b8cbd1e03
  • cef-1.5.0: efec721addb7513d
  • checkpoint-1.4.0: 1e21938fe162a407
  • cisco_asa-2.3.0: 7158c5ef2eb3f9e0
  • cisco_duo-1.2.1: 9d27cd7c22516e90
  • cisco_ftd-2.1.0: 7e86497dae176ef0
  • cisco_ios-1.5.0: cd5f37b0f95055c5
  • cisco_ise-0.1.0: 0d38863b06c7af4a
  • cisco_meraki-0.5.0: 743006b722fca63b
  • cisco_nexus-0.5.1: 0b06fb8e1d7621d0
  • cisco_secure_email_gateway-0.1.0: dfcd7297dc1f5859
  • cisco_secure_endpoint-2.4.0: e4d6546eb54d463d
  • cisco_umbrella-0.6.1: 18ff79b01813b49f
  • cloudflare-1.4.2: 03f7a745f0541f07
  • crowdstrike-1.3.1: 7b299fef3eff711c
  • cyberarkpas-2.4.0: 79511607d9c18fb1
  • cylance-0.8.0: 58f54595558a4e54
  • f5-0.9.0: 27add7bb1938bed6
  • fim-0.1.0: 6ddba304cf0c26d2
  • fireeye-1.3.0: e71ca563df7980ad
  • fortinet-1.5.0: 7927edfde242c389
  • gcp-1.6.1: 30a38c871b342272
  • github-0.4.0: 13f60a7c9e403527
  • google_workspace-1.4.0: 5c77ba126e223bde
  • hashicorp_vault-1.4.0: 7eb534c7910e6b56
  • http_endpoint-1.1.0: a8ac4656ad2e184f
  • httpjson-1.2.0: 423f936b9d2eafd4
  • imperva-0.8.0: 337d1b870908e79f
  • infoblox-0.8.0: 5b8526fe2dda9838
  • infoblox_nios-0.1.0: ad4ee89603da30d7
  • iptables-0.9.0: 908518e12e61db46
  • juniper_junos-0.2.0: 67f477896a824fea
  • juniper_netscreen-0.2.0: 5172afecd647f8a2
  • juniper_srx-1.2.0: fc0d0a9c302be3f1
  • keycloak-1.3.0: de3ac230dfed707d
  • mattermost-1.2.0: 4192eb1f66f72158
  • microsoft_defender_endpoint-2.2.0: f933038be7b6e50d
  • microsoft_dhcp-1.4.0: ee831c55d10cada5
  • microsoft_sqlserver-0.5.0: 4bcf70ed831b2ea6
  • mimecast-0.0.11: ff9c21c52be9264a
  • netflow-1.5.0: bc696ea5a30c6c61
  • netscout-0.8.0: 85c9501ee480284b
  • network_traffic-0.9.0: 32f9e1c4d52b9323
  • o365-1.5.1: 452a2ab3c36c67cb
  • okta-1.6.0: e2ef07afea5c3b29
  • osquery-1.3.0: ad3fb5421013a549
  • panw-1.6.0: 0699785fd464d4b6
  • panw_cortex_xdr-1.2.0: b94d085f4ced7d9a
  • pfsense-0.4.0: 0ed3f944c02e9339
  • proofpoint-0.7.0: beb155e072c10d07
  • pulse_connect_secure-0.3.0: 6dc70ed79ff2f2c6
  • qnap_nas-1.2.0: 9e411ac33be335b1
  • radware-0.7.0: 47abf7e3d3aa6c65
  • santa-2.1.0: c518cf944b181cff
  • snort-0.3.0: ea185dce1cfcc1dd
  • snyk-1.2.0: bb69358c6bb84617
  • sonicwall-0.8.0: a4d3ad415294109a
  • sophos-2.1.0: 734e04a9119c64bb
  • squid-0.8.0: 5209100c389b158e
  • suricata-1.7.0: 9f3c904110cdee53
  • tcp-1.1.0: 83f18c690a6797d4
  • tenable_sc-1.2.0: fb96ff8d458aa314
  • ti_abusech-1.3.0: 4be6b3f1da9398a6
  • ti_anomali-1.3.0: 221bff33f07cbb19
  • ti_cybersixgill-1.4.0: 8a6a617dc4453bbf
  • ti_misp-1.3.0: d0ca45bdd82ae4fa
  • ti_otx-1.3.0: 7154d03aafc76965
  • ti_threatq-1.3.0: 9375a5514a84c5ee
  • tomcat-1.4.0: 6e3388589e7f9afb
  • udp-1.1.0: bf05378fc8f50fa5
  • winlog-1.5.0: 9c18f534dd17c37a
  • zeek-1.8.0: c133ae10764ab897
  • zerofox-1.3.0: a2cc11672c1c07ec
  • zoom-1.3.1: 06901f13e37fa479
  • zscaler_zia-2.0.0: dd3ed88359e6e184
  • zscaler_zpa-0.2.0: 5cad0958c8ce3c2c

Summary of Fleet Package Changes

Report generated from snapshot branch commit
f5e5cdd74c0ebf01a1e94c9ed77090e22e0d521a
from 2022-05-02 15:02:57 +0000 UTC.

Comparisons were made to production branch commit
0e4e40d4ceee73e6c9d89ff712e84bde3ac167ef
from 2022-05-02 13:46:49 +0000 UTC.

Filtering parameters:

  • Team: elastic/security-external-integrations

  • Include Deprecated: false

1Password Events Reporting - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.2.2

  • 1.3.0
    • enhancement: Update to ECS 8.2 (PR)

Akamai - 0.2.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 0.1.3

  • 0.2.0
    • enhancement: Update to ECS 8.2 (PR)

Atlassian Bitbucket - 1.2.1

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.1.1

  • 1.2.1

    • enhancement: Update Readme (PR)
  • 1.2.0

    • enhancement: Update to ECS 8.2 (PR)

Atlassian Confluence - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.1.2

  • 1.3.0

    • enhancement: Add support for Atlassian Confluence Cloud (PR)
  • 1.2.0

    • enhancement: Update to ECS 8.2 (PR)

Atlassian Jira - 1.2.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.1.2

  • 1.2.0
    • enhancement: Update to ECS 8.2 (PR)

Auditd - 2.2.0

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

Changes since 2.1.2

  • 2.2.0
    • enhancement: Update to ECS 8.2 (PR)

Barracuda Logs - 0.9.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 0.8.0

  • 0.9.0
    • enhancement: Update to ECS 8.2.0 (PR)

Blue Coat Director Logs - 0.8.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 0.7.0

  • 0.8.0
    • enhancement: Update to ECS 8.2.0 (PR)

VMware Carbon Black Cloud - 0.1.2

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

Changes since 0.1.1

  • 0.1.2
    • enhancement: Add "VMware" to the title to make it "VMware Carbon Black Cloud". (PR)

VMware Carbon Black EDR - 1.2.0

Owner: elastic/security-external-integrations

Requires: ^7.14.0 || ^8.0.0

Changes since 1.1.1

  • 1.2.0
    • enhancement: Update to ECS 8.2 (PR)

CEF Logs - 1.5.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.4.3

  • 1.5.0
    • enhancement: Update to ECS 8.2 by modifying Check Point events to use the new email field set. (PR)

Check Point - 1.4.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.3.6

  • 1.4.0
    • enhancement: Update to ECS 8.2 to use new email field set. (PR)

Cisco ASA - 2.3.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 2.2.1

  • 2.3.0

    • enhancement: Update to ECS 8.2 (PR)
  • 2.2.2

    • bugfix: Change visualizations to use event.code instead of cisco.asa.message_id. (PR)

Cisco Duo - 1.2.1

Owner: elastic/security-external-integrations

Requires: ^7.17.2 || ^8.0.0

Changes since 1.1.4

  • 1.2.1

    • enhancement: Added link to Duo documentation (PR)
  • 1.2.0

    • enhancement: Update to ECS 8.2 (PR)
  • 1.1.6

    • enhancement: Simplify IP grok patterns. (PR)
  • 1.1.5

    • bugfix: Fix handling of IP addresses with port numbers. (PR)

Cisco FTD - 2.1.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 2.0.4

  • 2.1.0
    • enhancement: Update to ECS 8.2 (PR)

Cisco IOS - 1.5.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.4.2

  • 1.5.0
    • enhancement: Update to ECS 8.2 (PR)

Cisco ISE - 0.1.0

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

New Package

  • 0.1.0
    • enhancement: Initial draft of the package (PR)

Cisco Meraki Integration - 0.5.0

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

Changes since 0.4.1

  • 0.5.0
    • enhancement: Replace RSA2ELK with Syslog and Webhook integration (PR)

Cisco Nexus - 0.5.1

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 0.4.1

  • 0.5.1

    • enhancement: Updated readme file (PR)
  • 0.5.0

    • enhancement: Update to ECS 8.2.0 (PR)

Cisco Secure Email Gateway - 0.1.0

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

New Package

  • 0.1.0
    • enhancement: Initial draft of the package (PR)

Cisco Secure Endpoint (AMP) - 2.4.0

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

Changes since 2.3.1

  • 2.4.0
    • enhancement: Update to ECS 8.2 (PR)

Cisco Umbrella - 0.6.1

Owner: elastic/security-external-integrations

Requires: ^8.0.0

Changes since 0.5.1

  • 0.6.1

    • bugfix: Fix use of destination.ip instead of source.nat.ip in DNS logs (PR)
  • 0.6.0

    • enhancement: Update to ECS 8.2 (PR)

Cloudflare - 1.4.2

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.3.2

  • 1.4.2

    • enhancement: Update documentation (PR)
  • 1.4.1

    • enhancement: Add _id field to the logpull data stream to deduplicate events. (PR)
  • 1.4.0

    • enhancement: Update to ECS 8.2 (PR)

CrowdStrike Logs - 1.3.1

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.2.7

  • 1.3.1

    • enhancement: Update readme file. Added link to CrowdStrike docs (PR)
  • 1.3.0

    • enhancement: Update to ECS 8.2 (PR)

CyberArk Privileged Access Security Logs - 2.4.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 2.3.2

  • 2.4.0
    • enhancement: Update to ECS 8.2 (PR)

CylanceProtect Logs - 0.8.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 0.7.0

  • 0.8.0
    • enhancement: Update to ECS 8.2.0 (PR)

F5 Logs - 0.9.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 0.8.0

  • 0.9.0
    • enhancement: Update to ECS 8.2.0 (PR)

File Integrity Monitoring - 0.1.0

Owner: elastic/security-external-integrations

Requires: ^8.3.0

New Package

  • 0.1.0
    • enhancement: Initial version (PR)

Fireeye - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.2.2

  • 1.3.0

    • enhancement: Update to ECS 8.2 (PR)
  • 1.2.4

    • bugfix: Move invalid field values (PR)
  • 1.2.3

    • bugfix: Fix typo in config template for ignoring host enrichment (PR)

Fortinet Logs - 1.5.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 1.4.3

  • 1.5.0
    • enhancement: Update to ECS 8.2.0 to use new email field set. (PR)

Google Cloud Platform - 1.6.1

Owner: elastic/security-external-integrations

Requires: ^7.16.3 || ^8.0.0

Changes since 1.5.1

  • 1.6.1

    • enhancement: Clarify the GCP privileges required by the Pub/Sub input. (PR)
  • 1.6.0

    • enhancement: Update to ECS 8.2 (PR)

GitHub - 0.4.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 0.3.4

  • 0.4.0
    • enhancement: Update to ECS 8.2 (PR)

Google Workspace Audit Reports - 1.4.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.3.3

  • 1.4.0

    • enhancement: Update to ECS 8.2 (PR)
  • 1.3.4

    • bugfix: Fix pagination to prevent skipped events when more than one page is present. (PR)

Hashicorp Vault - 1.4.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.3.3

  • 1.4.0
    • enhancement: Update to ECS 8.2 (PR)

Custom HTTP Endpoint Logs - 1.1.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.0.1

  • 1.1.0
    • enhancement: Update ECS to 8.2 (PR)

Custom HTTPJSON Input - 1.2.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.1.1

  • 1.2.0
    • enhancement: Update ECS to 8.2 (PR)

Imperva SecureSphere Logs - 0.8.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 0.7.0

  • 0.8.0
    • enhancement: Update to ECS 8.2.0 (PR)

Infoblox NIOS Logs - 0.8.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 0.7.0

  • 0.8.0
    • enhancement: Update to ECS 8.2.0 (PR)

Infoblox NIOS - 0.1.0

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

New Package

  • 0.1.0
    • enhancement: Initial draft of the package. (PR)

Iptables Logs - 0.9.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 0.8.1

  • 0.9.0
    • enhancement: Update to ECS 8.2 (PR)

Juniper JunOS - 0.2.0

Owner: elastic/security-external-integrations

Requires: ^8.0.0

Changes since 0.1.1

  • 0.2.0
    • enhancement: Update to ECS 8.2.0 (PR)

Juniper NetScreen - 0.2.0

Owner: elastic/security-external-integrations

Requires: ^8.0.0

Changes since 0.1.1

  • 0.2.0
    • enhancement: Update to ECS 8.2.0 (PR)

Juniper SRX - 1.2.0

Owner: elastic/security-external-integrations

Requires: ^8.0.0

Changes since 1.1.2

  • 1.2.0
    • enhancement: Update to ECS 8.2 (PR)

Keycloak - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.2.1

  • 1.3.0
    • enhancement: Update to ECS 8.2 (PR)

Mattermost - 1.2.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.1.1

  • 1.2.0
    • enhancement: Update to ECS 8.2 (PR)

Microsoft Defender for Endpoint - 2.2.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 2.1.0

  • 2.2.0
    • enhancement: Update to ECS 8.2 (PR)

Microsoft DHCP - 1.4.0

Owner: elastic/security-external-integrations

Requires: ^7.14.0 || ^8.0.0

Changes since 1.3.1

  • 1.4.0
    • enhancement: Update to ECS 8.2 (PR)

Microsoft SQL Server - 0.5.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 0.4.5

  • 0.5.0
    • enhancement: Update to ECS 8.2 (PR)

Mimecast - 0.0.11

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

New Package

  • 0.0.11

    • enhancement: Update integration description for consistency with other integrations. (PR)
    • bugfix: Add missing ECS event.* field mappings. (PR)
  • 0.0.10

    • enhancement: Add more use cases to audit_events pipeline (PR)
    • enhancement: Implement geo.ip for siem logs (PR)
    • enhancement: Remove user part for ttp-url logs and add email.to.address for recipient (PR)
  • 0.0.9

    • enhancement: Update ecs to version 8.2.0 and implement better practice for email ECS fields. (PR)
  • 0.0.8

    • enhancement: Add documentation for multi-fields (PR)
  • 0.0.7

    • bugfix: Add content-disposition to test mock to properly create sample event from SIEM logs. (PR)
  • 0.0.6

    • enhancement: Add use cases for audit events and update sample events and docs (PR)
  • 0.0.5

    • bugfix: Fix typo (PR)
    • bugfix: Add 8.0.0 compatibility, fix team name in manifest, and remove redundant event.ingested from pipelines. (PR)
  • 0.0.4

    • bugfix: Regenerate test files using the new GeoIP database (PR)
  • 0.0.3

    • bugfix: Change test public IPs to the supported subset (PR)
  • 0.0.2

    • enhancement: Tweaking the dashboards (PR)
  • 0.0.1

    • enhancement: Initial draft of the package (PR)

NetFlow Records - 1.5.0

Owner: elastic/security-external-integrations

Requires: ^7.14.0 || ^8.0.0

Changes since 1.4.2

  • 1.5.0
    • enhancement: Update to ECS 8.2 (PR)

Arbor Peakflow SP Logs - 0.8.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 0.7.0

  • 0.8.0
    • enhancement: Update to ECS 8.2.0 (PR)

Network Packet Capture - 0.9.0

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

Changes since 0.8.1

  • 0.9.0

    • enhancement: Update to ECS 8.2 (PR)
  • 0.8.2

    • bugfix: Add missing field mappings to DNS and TLS data streams. (PR)

Office 365 Logs - 1.5.1

Owner: elastic/security-external-integrations

Requires: ^7.14.0 || ^8.0.0

Changes since 1.4.3

  • 1.5.1

    • bugfix: Fix processing of ModifiedProperties when it is a list of strings (PR)
  • 1.5.0

    • enhancement: Update to ECS 8.2 (PR)

Okta Logs - 1.6.0

Owner: elastic/security-external-integrations

Requires: ^7.14.0 || ^8.0.0

Changes since 1.5.2

  • 1.6.0
    • enhancement: Update to ECS 8.2 (PR)

Osquery Logs - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^7.14.0 || ^8.0.0

Changes since 1.2.1

  • 1.3.0
    • enhancement: Update to ECS 8.2 (PR)

Palo Alto Networks Logs - 1.6.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.5.3

  • 1.6.0
    • enhancement: Update to ECS 8.2 (PR)

Palo Alto Cortex XDR Logs - 1.2.0

Owner: elastic/security-external-integrations

Requires: ^7.15.0 || ^8.0.0

Changes since 1.1.1

  • 1.2.0
    • enhancement: Update to ECS 8.2 to use new email field set. (PR)

pfSense Logs - 0.4.0

Owner: elastic/security-external-integrations

Requires: ^7.15.0 || ^8.0.0

Changes since 0.3.1

  • 0.4.0
    • enhancement: Update to ECS 8.2 (PR)

Proofpoint Email Security Logs - 0.7.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 0.6.0

  • 0.7.0
    • enhancement: Update to ECS 8.2.0 (PR)

Pulse Connect Secure - 0.3.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 0.2.1

  • 0.3.0
    • enhancement: Update to ECS 8.2 (PR)

QNAP NAS - 1.2.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.1.1

  • 1.2.0
    • enhancement: Update to ECS 8.2 (PR)

Radware DefensePro Logs - 0.7.0

Owner: elastic/security-external-integrations

Requires: ^7.14.0 || ^8.0.0

Changes since 0.6.0

  • 0.7.0
    • enhancement: Update to ECS 8.2.0 (PR)

Google Santa Logs - 2.1.0

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

Changes since 2.0.1

  • 2.1.0
    • enhancement: Update to ECS 8.2 (PR)

Snort - 0.3.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 0.2.2

  • 0.3.0
    • enhancement: Update to ECS 8.2 (PR)

Snyk - 1.2.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.1.2

  • 1.2.0
    • enhancement: Update to ECS 8.2 (PR)

Sonicwall-FW Logs - 0.8.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 0.7.1

  • 0.8.0
    • enhancement: Update to ECS 8.2.0 (PR)

Sophos Logs - 2.1.0

Owner: elastic/security-external-integrations

Requires: ^7.17.0 || ^8.0.0

Changes since 1.2.2

  • 2.1.0

    • enhancement: Update to ECS 8.2.0 to use new email field set. (PR)
  • 2.0.0

    • bugfix: Remove space from sophos.xg.trans_src_ip field. (PR)
    • bugfix: Do not modify event.original. (PR)
    • enhancement: Populate url.* fields based on sophos.xg.url. (PR)
    • enhancement: Rename sophos.xg.reason to event.reason (ECS). (PR)
    • bugfix: Lowercase network.transport as per ECS. (PR)
    • bugfix: Format source.mac and destination.mac as per ECS. (PR)
    • enhancement: Set the event.code from the message ID (and remove sophos.xg.message_id). (PR)
    • enhancement: Add network.community_id. (PR)
    • breaking-change: Reduce event size by removing client and server fields that are clones of source and destination, respectively. (PR)
  • 1.2.3

    • enhancement: Update pipelines to parse new fields (PR)

Squid Logs - 0.8.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 0.7.0

  • 0.8.0
    • enhancement: Update to ECS 8.2.0 (PR)

Suricata Events - 1.7.0

Owner: elastic/security-external-integrations

Requires: ^7.14.0 || ^8.0.0

Changes since 1.6.1

  • 1.7.0
    • enhancement: Update to ECS 8.2 (PR)

Custom TCP Logs - 1.1.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.0.0

  • 1.1.0
    • enhancement: Update to ECS 8.2 (PR)

Tenable.sc - 1.2.0

Owner: elastic/security-external-integrations

Requires: ^8.1.0

Changes since 1.1.1

  • 1.2.0
    • enhancement: Update to ECS 8.2 (PR)

AbuseCH - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^8.0.0

Changes since 1.2.3

  • 1.3.0
    • enhancement: Update to ECS 8.2 (PR)

Anomali - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^8.0.0

Changes since 1.2.3

  • 1.3.0
    • enhancement: Update to ECS 8.2 (PR)

Cybersixgill - 1.4.0

Owner: elastic/security-external-integrations

Requires: ^8.0.0

Changes since 1.3.2

  • 1.4.0
    • enhancement: Update to ECS 8.2 (PR)

MISP - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^8.0.0

Changes since 1.2.2

  • 1.3.0
    • enhancement: Update to ECS 8.2 (PR)

AlienVault OTX - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^8.0.0

Changes since 1.2.2

  • 1.3.0
    • enhancement: Update to ECS 8.2 (PR)

ThreatQuotient - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^8.0.0

Changes since 1.2.2

  • 1.3.0
    • enhancement: Update to ECS 8.2 (PR)

Apache Tomcat - 1.4.0

Owner: elastic/security-external-integrations

Requires: ^7.14.1 || ^8.0.0

Changes since 1.3.1

  • 1.4.0
    • enhancement: Update to ECS 8.2.0 (PR)

Custom UDP Logs - 1.1.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.0.1

  • 1.1.0
    • enhancement: Update ECS to 8.2 (PR)

Custom Windows Event Logs - 1.5.0

Owner: elastic/security-external-integrations

Requires: ^7.16.0 || ^8.0.0

Changes since 1.4.0

  • 1.5.0
    • enhancement: Update to ECS 8.2 (documentation reference only) (PR)

Zeek Logs - 1.8.0

Owner: elastic/security-external-integrations

Requires: ^7.14.0 || ^8.0.0

Changes since 1.6.1

  • 1.8.0

    • bugfix: Make sure field values are valid for ECS (PR)
  • 1.7.0

    • enhancement: Update to ECS 8.2 (PR)

ZeroFox - 1.3.0

Owner: elastic/security-external-integrations

Requires: ^7.14 || ^8.0.0

Changes since 1.2.1

  • 1.3.0
    • enhancement: Update to ECS 8.2 (PR)

Zoom - 1.3.1

Owner: elastic/security-external-integrations

Requires: ^7.14.0 || ^8.0.0

Changes since 1.2.1

  • 1.3.1

    • bugfix: Fix content-type handling. (PR)
  • 1.3.0

    • enhancement: Update to ECS 8.2 (PR)

Zscaler Internet Access - 2.0.0

Owner: elastic/security-external-integrations

Requires: ^8.3.0

Changes since 0.1.3

  • 2.0.0

    • enhancement: Added input for Cloud NSS using HTTP Endpoint input type. (PR)
  • 0.2.0

    • enhancement: Update ECS to 8.2 (PR)

Zscaler Private Access - 0.2.0

Owner: elastic/security-external-integrations

Requires: ^7.16.2 || ^8.0.0

Changes since 0.1.2

  • 0.2.0
    • enhancement: Update ECS to 8.2 (PR)

@andrewkroh andrewkroh self-assigned this May 2, 2022
@andrewkroh andrewkroh added the Team:Security-External Integrations Label for the Security External Integrations team label May 2, 2022
@elasticmachine
Copy link
Collaborator

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2022-05-02T17:39:30.524+0000

  • Duration: 33 min 29 sec

Test stats 🧪

Test Results
Failed 0
Passed 69
Skipped 0
Total 69

Copy link

@taylor-swanson taylor-swanson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@andrewkroh andrewkroh merged commit c793968 into elastic:production May 3, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Team:Security-External Integrations Label for the Security External Integrations team
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants