-
Notifications
You must be signed in to change notification settings - Fork 441
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
SysmonForLinux | New integration to support Sysmon logs for Linux #4531
Conversation
🚀 Benchmarks reportTo see the full report comment with |
🌐 Coverage report
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just leaving some high level comments. I did not review the ingest node pipeline.
packages/sysmon/data_stream/log/_dev/test/pipeline/test-common-config.yml
Outdated
Show resolved
Hide resolved
packages/sysmon/data_stream/log/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/sysmon/data_stream/log/_dev/test/pipeline/test-sysmon.json-expected.json
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Outside of some small things it seems good. Lets resolve Andrews comments first.
Package sysmon_linux - 0.1.0 containing this change is available at https://epr.elastic.co/search?package=sysmon_linux |
Great to see this come to life 🙌 |
What does this PR do?
This new integration adds support for syslog from Sysmon events in Linux environments
Checklist
changelog.yml
file.Related issues