-
Notifications
You must be signed in to change notification settings - Fork 462
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add Kubernetes CIS Benchmark integration #2920
Closed
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Automated PR. Upgrades rsa2elk package to ECS 8.0.0.
Automated PR. Upgrades rsa2elk package to ECS 8.0.0.
Automated PR. Upgrades rsa2elk package to ECS 8.0.0.
Automated PR. Upgrades rsa2elk package to ECS 8.0.0.
Automated PR. Upgrades rsa2elk package to ECS 8.0.0.
Automated PR. Upgrades rsa2elk package to ECS 8.0.0.
Automated PR. Upgrades rsa2elk package to ECS 8.0.0.
Automated PR. Upgrades rsa2elk package to ECS 8.0.0.
Automated PR. Upgrades rsa2elk package to ECS 8.0.0.
Automated PR. Upgrades rsa2elk package to ECS 8.0.0. Closes elastic#2425
Automated PR. Upgrades rsa2elk package to ECS 8.0.0. Includes manual changes to xg data stream from elastic#2441 Closes elastic#2441 Co-authored-by: Sai Kiran <[email protected]>
* Schedule daily: test packages against 8.1 * Bump up 7.16 to 7.17
Mark tenable_sc as GA and bump to 1.0.0.
* Regenerate pipeline test events * Remove event.ingested * Use allowed geoip test IPs in test logs * Use convert processor to set source/destination.ip * Format MAC addresses per RFC 7042 and ECS * Don't override event.{created,original} when reindexing * Use triple braces in templates or set.copy_from * Add changelog
…ic#2605) * [Security Rules] Update security rules package to v1.0.0-dev.0 * Add changelog entry for 1.0.0-dev.0 * Update package version to 1.0.1
* Add missing job.name and cronjob.name meta fields Signed-off-by: ChrsMark <[email protected]> * Fix changelog Signed-off-by: ChrsMark <[email protected]>
) * fix: add missing fields for browser synthetics integration [fix elastic/kibana#123479] * update browser mappings * add screenshot_ref and duration mappings * move browser fields to root Co-authored-by: Dominique Clarke <[email protected]>
…lastic#2612) * Add missing job and cronjob fields in container related metricsets Signed-off-by: ChrsMark <[email protected]> * Add PR number in changelog Signed-off-by: ChrsMark <[email protected]>
…c#2615) Bumps [github.com/elastic/elastic-package](https://github.com/elastic/elastic-package) from 0.34.1 to 0.35.0. - [Release notes](https://github.com/elastic/elastic-package/releases) - [Changelog](https://github.com/elastic/elastic-package/blob/main/.goreleaser.yml) - [Commits](elastic/elastic-package@v0.34.1...v0.35.0) --- updated-dependencies: - dependency-name: github.com/elastic/elastic-package dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* fixing typo in httpjson.yml.hbs * Update changelog
elastic#2888) * Extract potential host.domain and user.domain * Bump version to 2.0.1 Bump version * Update changelog.yml * Fixes Needed to use cisco.secure_endpoint.computer.hostname instead of host.name * updating CI tests and adding some minor changes * adding some small modifications to pipeline * adding some small changes based on PR review * update docs Co-authored-by: Marius Iversen <[email protected]>
…c#2899) Bumps [github.com/elastic/elastic-package](https://github.com/elastic/elastic-package) from 0.42.0 to 0.43.0. - [Release notes](https://github.com/elastic/elastic-package/releases) - [Changelog](https://github.com/elastic/elastic-package/blob/main/.goreleaser.yml) - [Commits](elastic/elastic-package@v0.42.0...v0.43.0) --- updated-dependencies: - dependency-name: github.com/elastic/elastic-package dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Fix dns.id & network.iana_number field mappings.
Fix field mapping conflicts in threat.indicator.file.x509.not_before/not_after.
Fix field conflict for winlog.record_id.
Fix field mapping conflicts for checkpoint.icmp_type, checkpoint.icmp_code & checkpoint.email_recipients_num.
* adds ml_problem_child package * add ml_module to problem child package * ensure modules in right path. update query * fix jobs configs * move datafeeds into attributes * update ingest pipeline name and update job configs * remove hardcoded indices for datafeeds. update descriptions * adds job groups and security rules * update deprecated property and package manifest minimum version * format files * rename package folder. update logo * fix encoding error * update package name to match validation pattern. fix encoding in rule * Add (experimental) to job descriptions) * update README with more asset info * add license requirement to card and readme * add asset context to readme * update card title and description * update overview config section with more instructions * change back to basic license but add platinum subscription language and notice * update codeowners file * update codeowners and readme * update owners in manifest * ensure files formatted correctly * update ml_module asset id to match filename * rename problem_child directory to problemchild for consistency * update ml module id to match filename * fix module id
Add configuration for max_number_of_messages to the aws.firewall_logs S3 input.
Added `forwarded` tags for Azure logs.
* adds ml_dga package * adds ml_problem_child package * adds dga pipelines * update license type requirement to platinum * rename model files to model id * fix dga pipeline * remove problem child package. add module to dga package * adds security rules to dga package * update minimum version requirement and deprecated model property * format json files * update icon. add groups to ad job * rename directory * update pipeline description * update readme with asset info * add license requirement to card and readme * add asset context to readme * add updated subscription language and update codeowners file * update readme and add security tag * fix ml-module file id
…c#2891) Fix event.duration field conflict in Azure Logs.
Fix event.* field mappings and conflicts.
* append a newline character to the last line of the log enabling filebeat log input multiline reader to pass the entire block to the pipeline.
❌ Author of the following commits did not sign a Contributor Agreement: Please, read and sign the above mentioned agreement if you want to contribute to this project |
💔 Build Failed
Expand to view the summary
Build stats
Steps errorsExpand to view the steps failures
|
…tions into add-cis-benchmark
eyalkraft
force-pushed
the
add-cis-benchmark
branch
from
March 30, 2022 13:11
781ae38
to
547ff49
Compare
4 tasks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Adds the initial version of the Kuberenetes CIS Benchmark integration.
Checklist
changelog.yml
file.Notes
example
taken from here
This is due to the fact that the tranforms expect some existing indices - these indices are created by the plugin.
Enabling the plugin is done by setting
xpack.cloudSecurityPosture.enabled: true
inkibana.yml
. By default the plugin is disabled.This is documented in the integration doc.
example for installation attempt when the plugin isn't enabled
Author's Checklist
How to test this PR locally
Related issues
Screenshots