Skip to content

Conversation

@threat-punter
Copy link
Contributor

@threat-punter threat-punter commented Sep 15, 2020

Issues

#255

Summary

This PR updates our prebuilt Okta rules to include the Elastic Agent index, `logs-okta*.

image

Contributor checklist

Copy link
Contributor

@bm11100 bm11100 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🚀

Copy link
Contributor

@brokensound77 brokensound77 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This LGTM

As a note, validation for any non ECS (module-specific) fields passes due to the inclusion of the filebeat-* index. So if a module specific rule ever targets a logs-* index exclusively, it may not pass validation (We would need to update the validation)

@threat-punter threat-punter merged commit 4041fc8 into elastic:main Sep 15, 2020
@threat-punter threat-punter deleted the update-okta-rules-for-ingest-manager-compatibility branch September 15, 2020 21:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Domain: Cloud Workloads Integration: Okta okta related rules Rule: Tuning tweaking or tuning an existing rule v7.10.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants