elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
21 stars 435 forks source link

Windows Custom Event Logs - add support for multiple channels #5877

Open jmyns opened 1 year ago

jmyns commented 1 year ago

Currently the windows custom event integration only allows adding a single event channel. Add support for multiple event channels.

I noticed I can add multiple packages using the fleet api but kibana only shows the first package - so this may only require a minimal change in kibana to handle the package_policy array.

There are a few other feature requests which mention this as part of a larger enhancement.

https://github.com/elastic/integrations/issues/4564 https://github.com/elastic/integrations/issues/784

elasticmachine commented 1 year ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)