elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
196 stars 426 forks source link

Update Description Text for Threat Intelligence Integration Packages #2831

Closed shimonmodi closed 1 year ago

shimonmodi commented 2 years ago

Context: With the latest release of 8.1 there are multiple integration packages available for threat intelligence. We want to update the description for each threat intelligence integration package available in "Integrations" page in-product to be consistent and align with end user expectations.

Checklist: Update description for each integration package with the following:

jamiehynds commented 2 years ago

Thanks @shimonmodi - can you clarify the MISP title change? Did you want to change the Filebeat module title to ensure users are aware it's a Filebeat module, but keep the agent integration name intact? For some reason, when you search for 'threat', the MISP filebeat module returns, but not the agent integration. Would love to figure that one out too.

shimonmodi commented 2 years ago

@jamiehynds - thats correct. The only change is to the title of the MISP Filebeat module. The agent integration is accurately titled and doesn't need any change.

As for MISP filebeat module only showing up when searching for threat, the only reason I can think of is that a text search is being executed. MISTP Filebeat currently has threat intel logs in the title, but MISP agent integration doesn't. When we update the description text it should show up.

Which means we will want to update the description text for MISP (the agent integration as well). I will update the check list to reflect that.

elasticmachine commented 2 years ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

jamiehynds commented 2 years ago

I spoke with a user today, who didn't realise we have a MISP integration with agent, due to it not appearing within the integrations page under a 'threat intelligence' search.

On the overview page of the Security app, we have a link to enable TI sources:

Screenshot 2022-04-27 at 15 16 04

This takes you to the integrations page, pre-populated with a search for "Threat Intelligence". MISP agent integration doesn't appear as it the description doesn't include "threat intelligence"

Screenshot 2022-04-27 at 15 16 26
jamiehynds commented 1 year ago

Closing as the task was completed.