elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
196 stars 427 forks source link

[ForgeRock] Add idm_recon events #9637

Open roman-peeters opened 5 months ago

roman-peeters commented 5 months ago

According to the ForgeRock documentation there is an additional topic for audit events: idm-recon.

It would be an improvement to add these idm-recon events to the Elastic Integration similar as all the other topics are already included in the integration.

elasticmachine commented 5 months ago

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

efd6 commented 3 months ago

@roman-peeters That link requires an account. Are you able to share example logs/documentation for this topic?

roman-peeters commented 3 months ago

@efd6 I see that they have moved the documentation. Normally this link should work: https://backstage.forgerock.com/docs/idcloud/latest/tenants/audit-debug-logs.html#source-descriptions

I made a screenshot of a relevant part: image

The "idm-recon" audit event topic is similar to the "idm-sync" or "idm-core" topics which are already included for the integration.

efd6 commented 3 months ago

Thanks @roman-peeters. Are you able to provide a small number of sanitised examples that we can use for testing?