Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add CrowdStrike filebeat module #182

Merged
merged 11 commits into from
Aug 4, 2020

Conversation

andrewstucki
Copy link
Contributor

@andrewstucki andrewstucki commented Jul 21, 2020

What does this PR do?

So, one of the things in the handlebars yaml file to bring it to parity with what's currently in filebeat is blocked by elastic/kibana#72698

I'm going to try and actually test this locally as well, but I'm putting this up here early in case anyone wants to give early feedback.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all datasets collect metrics or logs.

Related issues

Screenshots

Screen Shot 2020-07-21 at 4 54 04 PM

Screen Shot 2020-07-21 at 4 54 13 PM

Screen Shot 2020-07-21 at 4 54 20 PM

Screen Shot 2020-08-04 at 11 23 00 AM

Screen Shot 2020-08-04 at 11 23 17 AM

Screen Shot 2020-08-04 at 12 12 45 PM

@andrewstucki andrewstucki added the enhancement New feature or request label Jul 21, 2020
@elasticmachine
Copy link

elasticmachine commented Jul 21, 2020

💚 Build Succeeded

Pipeline View Test View Changes Artifacts preview

Expand to view the summary

Build stats

  • Build Cause: [Pull request #182 updated]

  • Start Time: 2020-08-04T19:16:32.393+0000

  • Duration: 4 min 25 sec

@andrewstucki andrewstucki added Team:Integrations Label for the Integrations team Team:SIEM (Deprecated) labels Jul 21, 2020
@elasticmachine
Copy link

Pinging @elastic/siem (Team:SIEM)

@elasticmachine
Copy link

Pinging @elastic/integrations (Team:Integrations)

title: CrowdStrike SIEM Alerts
size: 3360x1776
type: image/jpg
- src: /img/siem-events-cs.jpg
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this appear in the Kibana UI? It looks like it's only showing the first screenshot right now?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I noticed the same thing with Suricata. I kind of expected to be able to thumb through the screenshots.

Copy link
Member

@andrewkroh andrewkroh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

packages/crowdstrike/manifest.yml Outdated Show resolved Hide resolved
@andrewstucki andrewstucki merged commit 5a19cc8 into elastic:master Aug 4, 2020
@andrewstucki andrewstucki deleted the filebeat-crowdstrike-falcon branch August 4, 2020 23:03
eyalkraft pushed a commit to build-security/integrations that referenced this pull request Mar 30, 2022
* Add crowdstrike filebeat module

* Update crowdstrike module

* Revert accidental removal

* Update with changes to crowdstrike module

* add back new samples

* Update base fields

* Update READMe

* update owner

* remove dataset fields and add in log and input fields

* remove stray png
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request Team:Integrations Label for the Integrations team Team:SIEM (Deprecated)
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Crowdstrike Filebeat Module
3 participants