elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
194 stars 418 forks source link

[stormshield] Follow-up tasks for new integration #10114

Open taylor-swanson opened 2 months ago

taylor-swanson commented 2 months ago

Inputs

ECS Improvements

New mappings (from existing vendor fields)

Cleanup

New mappings

1: ingress/egress depends on user-assignment (see fortigate for example). 2: Needs to be set based on contents of log. Other integrations use an log ID/event code to do this. We may only be able to use the log type, unless I'm missing something.

There may be other fields, this is what I saw on an initial look. As always, fortigate is a good integration to reference. Here's its ecs.yml as reference, and note that not all fields will be applicable here, it's just to get an idea of what's out there.

elasticmachine commented 2 months ago

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)