-
Notifications
You must be signed in to change notification settings - Fork 444
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[amazon_security_lake] Initial Release for Amazon Security Lake #7176
[amazon_security_lake] Initial Release for Amazon Security Lake #7176
Conversation
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
🌐 Coverage report
|
...e/data_stream/event/elasticsearch/ingest_pipeline/pipeline_category_application_activity.yml
Show resolved
Hide resolved
There are 1956 fields in the fields/*.yml files. This does not include the ECS field count because those are dynamically mapped. This means that the This is not a blocker, but we should discuss this with @P1llus when he is back. IIUC any time we use the ECS |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good. The dashboards are nice. I did not review the ingest pipelines.
|
||
## Compatibility | ||
|
||
This module follows the latest OCSF Schema Version **v1.0.0-rc.3**. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we highlight which OCSF classes are supported, as we're currently limited to Classes used only by the AWS Services.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey @jamiehynds ,
We have highlighted OCSF classes in data stream section which are supported in current integration. Do we need to also add here? Please let us know your thoughts.
| VPC Flow Logs | Network Activity | | ||
|
||
### **NOTE**: | ||
- The Amazon Security Lake integration supports events collected from [AWS services](https://docs.aws.amazon.com/security-lake/latest/userguide/internal-sources.html). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can we also a note here that we recommend ingesting data from these AWS Services via our out-of-the-box integrations to avail of more comprehensive ECS mappings and dashboards specific to each AWS service?
..._lake/data_stream/event/elasticsearch/ingest_pipeline/pipeline_category_network_activity.yml
Outdated
Show resolved
Hide resolved
..._lake/data_stream/event/elasticsearch/ingest_pipeline/pipeline_category_network_activity.yml
Outdated
Show resolved
Hide resolved
packages/amazon_security_lake/data_stream/event/elasticsearch/ingest_pipeline/default.yml
Show resolved
Hide resolved
packages/amazon_security_lake/data_stream/event/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/amazon_security_lake/data_stream/event/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM as my review comments are addressed. Please also address other reviews as well. Thanks!
Package amazon_security_lake - 0.1.0 containing this change is available at https://epr.elastic.co/search?package=amazon_security_lake |
What does this PR do?
Integration release checklist
This checklist is intended for integrations maintainers to ensure consistency
when creating or updating a Package, Module or Dataset for an Integration.
All changes
New Package
Dashboards changes
Log dataset changes
How to test this PR locally
Related issues
Automated Test
Screenshot