Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Jamf Protect] Adding AWS S3 as input type #9643

Merged
merged 6 commits into from
Apr 23, 2024

Conversation

txhaflaire
Copy link
Contributor

  • Bug

  • Added AWS-S3 Input to each data stream

  • Jamf Protect supports forwarding event data to AWS S3, this provides an alternative route alongside HTTP Endpoint

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

How to test this PR locally

--- Test results for package: jamf_protect - START ---
╭──────────────┬────────────────────┬───────────┬───────────────────────────────────────────────────────────────────────┬────────┬──────────────╮
│ PACKAGE      │ DATA STREAM        │ TEST TYPE │ TEST NAME                                                             │ RESULT │ TIME ELAPSED │
├──────────────┼────────────────────┼───────────┼───────────────────────────────────────────────────────────────────────┼────────┼──────────────┤
│ jamf_protect │                    │ asset     │ dashboard jamf_protect-e9b86210-c65c-11ee-882f-57f79af43d7f is loaded │ PASS   │     31.208µs │
│ jamf_protect │ alerts             │ asset     │ index_template logs-jamf_protect.alerts is loaded                     │ PASS   │        917ns │
│ jamf_protect │ alerts             │ asset     │ ingest_pipeline logs-jamf_protect.alerts-0.4.0 is loaded              │ PASS   │        291ns │
│ jamf_protect │ telemetry          │ asset     │ index_template logs-jamf_protect.telemetry is loaded                  │ PASS   │        500ns │
│ jamf_protect │ telemetry          │ asset     │ ingest_pipeline logs-jamf_protect.telemetry-0.4.0 is loaded           │ PASS   │        250ns │
│ jamf_protect │ web_threat_events  │ asset     │ index_template logs-jamf_protect.web_threat_events is loaded          │ PASS   │        334ns │
│ jamf_protect │ web_threat_events  │ asset     │ ingest_pipeline logs-jamf_protect.web_threat_events-0.4.0 is loaded   │ PASS   │        583ns │
│ jamf_protect │ web_traffic_events │ asset     │ index_template logs-jamf_protect.web_traffic_events is loaded         │ PASS   │        292ns │
│ jamf_protect │ web_traffic_events │ asset     │ ingest_pipeline logs-jamf_protect.web_traffic_events-0.4.0 is loaded  │ PASS   │        417ns │
╰──────────────┴────────────────────┴───────────┴───────────────────────────────────────────────────────────────────────┴────────┴──────────────╯
--- Test results for package: jamf_protect - END   ---
Done
Run pipeline tests for the package
2024/04/18 15:54:51 DEBUG Package does not embed ECS mappings
2024/04/18 15:54:52 DEBUG Package does not embed ECS mappings
2024/04/18 15:54:53 DEBUG Package does not embed ECS mappings
2024/04/18 15:54:53 DEBUG Package does not embed ECS mappings
--- Test results for package: jamf_protect - START ---
╭──────────────┬────────────────────┬───────────┬─────────────────────────────────────────────┬────────┬──────────────╮
│ PACKAGE      │ DATA STREAM        │ TEST TYPE │ TEST NAME                                   │ RESULT │ TIME ELAPSED │
├──────────────┼────────────────────┼───────────┼─────────────────────────────────────────────┼────────┼──────────────┤
│ jamf_protect │ alerts             │ pipeline  │ test-jamf-protect-alerts-sample-logs.log    │ PASS   │     22.116ms │
│ jamf_protect │ telemetry          │ pipeline  │ test-jamf-protect-telemetry-sample-logs.log │ PASS   │   6.936917ms │
│ jamf_protect │ web_threat_events  │ pipeline  │ test-jamf-protect-threat-sample-logs.log    │ PASS   │   5.245542ms │
│ jamf_protect │ web_traffic_events │ pipeline  │ test-jamf-protect-traffic-sample-logs.log   │ PASS   │   2.932541ms │
╰──────────────┴────────────────────┴───────────┴─────────────────────────────────────────────┴────────┴──────────────╯
--- Test results for package: jamf_protect - END   ---
Done
Run static tests for the package
2024/04/18 15:54:53 DEBUG Package does not embed ECS mappings
2024/04/18 15:54:54 DEBUG Package does not embed ECS mappings
2024/04/18 15:54:54 DEBUG Package does not embed ECS mappings
2024/04/18 15:54:54 DEBUG Package does not embed ECS mappings
--- Test results for package: jamf_protect - START ---
╭──────────────┬────────────────────┬───────────┬──────────────────────────┬────────┬──────────────╮
│ PACKAGE      │ DATA STREAM        │ TEST TYPE │ TEST NAME                │ RESULT │ TIME ELAPSED │
├──────────────┼────────────────────┼───────────┼──────────────────────────┼────────┼──────────────┤
│ jamf_protect │ alerts             │ static    │ Verify sample_event.json │ PASS   │  59.518959ms │
│ jamf_protect │ telemetry          │ static    │ Verify sample_event.json │ PASS   │  37.157375ms │
│ jamf_protect │ web_threat_events  │ static    │ Verify sample_event.json │ PASS   │  53.891417ms │
│ jamf_protect │ web_traffic_events │ static    │ Verify sample_event.json │ PASS   │  45.494791ms │
╰──────────────┴────────────────────┴───────────┴──────────────────────────┴────────┴──────────────╯
--- Test results for package: jamf_protect - END   ---
Done
Run system tests for the package
2024/04/18 15:54:54 DEBUG GET https://127.0.0.1:5601/api/status
--- Test results for package: jamf_protect - START ---
No test results
--- Test results for package: jamf_protect - END   ---
Done

Screenshots

image
image

@txhaflaire txhaflaire requested a review from a team as a code owner April 18, 2024 14:41
@ShourieG
Copy link
Contributor

/test

@elasticmachine
Copy link

🚀 Benchmarks report

Package jamf_protect 👍(3) 💚(0) 💔(1)

Expand to view
Data stream Previous EPS New EPS Diff (%) Result
alerts 1501.5 1077.59 -423.91 (-28.23%) 💔

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link

💚 Build Succeeded

Copy link

@jamiehynds jamiehynds added the Team:Security-Service Integrations Security Service Integrations Team [elastic/security-service-integrations] label Apr 19, 2024
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

Copy link
Contributor

@ShourieG ShourieG left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ShourieG ShourieG merged commit a19f4bc into elastic:main Apr 23, 2024
5 checks passed
@elasticmachine
Copy link

Package jamf_protect - 0.4.0 containing this change is available at https://epr.elastic.co/search?package=jamf_protect

@txhaflaire txhaflaire deleted the jamf_protect_0.4.0 branch April 23, 2024 08:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Integration:jamf_protect Jamf Protect Team:Security-Service Integrations Security Service Integrations Team [elastic/security-service-integrations]
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants