-
Notifications
You must be signed in to change notification settings - Fork 392
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
cef: make general purpose dashboards #3526
Conversation
🌐 Coverage report
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Could you please add screenshots to the PR description
Also consider embedding the visualizations in the dashboards by unlinking them or trying this inliner tool https://github.com/flash1293/legacy_vis_analyzer#inliner-usage.
The process for this was: clonedash -src $(pwd) -dry-run=false find kibana -name '*.json' -print0 | xargs -0 gsed -i -r 's/( via)? ArcSight//g; s!"/Attempt"!"unknown"!g; s!"/Success"!"success"!g; s!"/Failure"!"failure"!g; s!"query": "cef.extensions.categoryDeviceGroup:\\"/Operating System\\" OR cef.extensions.categoryDeviceGroup:\\"/IDS/Host\\" OR cef.extensions.categoryDeviceGroup:\\"/Application\\""!"query": "data_stream.dataset:\\"cef.log\\""!g; s/"cef\.extensions\.categoryBehavior"/"event.action"/g; s/"cef\.extensions\.categoryOutcome"/"event.outcome"/g; s/^(.*)"cef\.extensions\.categorySignificance"/\1"event.category",\n\1"event.type"/g;' git reset --hard
This dashboard depends on the ArcSight category "Device Group" which has no direct mapping in ECS or any fields in CEF that can be used to construct it in the general case, so degrade it to all endpoints from only operating system endpoints rather than losing the dashboard entirely.
A note on the origin of the data used to simulate for the dashboards. This is a general purpose CEF simulator that I will clean up for spigot. I needed to be customised for CheckPoint since that appears to be what the integration (along with Forcepoint) seems to be aimed at. |
What does this PR do?
This mirrors the ArcSight CEF dashboard where possible by mapping ArcSight extensions to ECS and removes visualisations and searches that are not expressible without those extensions.
Checklist
changelog.yml
file.Author's Checklist
How to test this PR locally
Related issues
Screenshots