-
Notifications
You must be signed in to change notification settings - Fork 458
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Cisco AMP] Add Cisco Secure Endpoint (AMP) package #1645
Conversation
💚 Build Succeeded
Expand to view the summary
Build stats
Test stats 🧪
🤖 GitHub commentsTo re-run your PR in the CI, just comment with:
|
packages/cisco_amp/data_stream/log/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/cisco_amp/data_stream/log/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
run tests |
/test |
packages/cisco_amp/data_stream/log/agent/stream/httpjson.yml.hbs
Outdated
Show resolved
Hide resolved
Cisco has renamed AMP to Secure Endpoint, I am a bit unsure how we would want to change it in terms of a few things: WDYT? |
304e2d4
to
3069aa2
Compare
/test |
@P1llus I think this is ready for review now that the system tests pass. The only open question is still the processors on the agent side. |
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
/test |
packages/cisco_secure_endpoint/data_stream/event/agent/stream/httpjson.yml.hbs
Outdated
Show resolved
Hide resolved
/test |
* elastic#1624: Add Cisco AMP package * Update changelog * Update to ECS 1.12 * rename to Cisco Secure Endpoint * update pipeline, system tests still not working * rename log dataset to event. Fix system tests * bump stream container version * bump strem version * move processors per comment
What does this PR do?
Add initial Cisco Secure Endpoint (AMP) package, migrated from Filebeat Module
Checklist
changelog.yml
file.manifest.yml
file to point to the latest Elastic stack release (e.g.^7.13.0
).Author's Checklist
How to test this PR locally
Related issues
Screenshots