New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
New Exchange Server integration #9197
Conversation
Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>
Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices) |
🚀 Benchmarks reportTo see the full report comment with |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I did an initial look over this, but I'll be diving deeper into the data streams next.
packages/microsoft_exchange_server/data_stream/smtp/manifest.yml
Outdated
Show resolved
Hide resolved
I feel like this integration would be better suited under the @elastic/sec-windows-platform team. @elastic/sec-deployment-and-devices primarily works with physical devices (routers, firewalls) where as this a Windows-exclusive application. While this currently reads from log files, I do believe Exchange can write to Windows Event Logs for at least some of its events, which would involve the winlog input. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looking good! Just couple of observations to simplify the pipelines if it makes sense.
PS: added them to the first one, but they apply to all pipelines
...es/microsoft_exchange_server/data_stream/httpproxy/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
...es/microsoft_exchange_server/data_stream/httpproxy/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
...es/microsoft_exchange_server/data_stream/httpproxy/elasticsearch/ingest_pipeline/default.yml
Show resolved
Hide resolved
Hi @marc-gr |
/test |
💚 Build Succeeded
History
|
Quality Gate passedKudos, no new issues were introduced! 0 New issues |
Package microsoft_exchange_server - 0.1.0 containing this change is available at https://epr.elastic.co/search?package=microsoft_exchange_server |
* initial commit new Exchange Server integration Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com> * Remove License file * change Codeowner * rename test-files for validation check * add validation.yml * Update Changelog, switch to filestream and fix docs * adjust manifest description * Change Codeowner * Added failure processors, switch to copy_from and remove duplicates --------- Co-authored-by: Simon Schneider <95302847+smnschneider@users.noreply.github.com>
Initial push of new developed Microsoft Exchange Server Integration (on-prem)