elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.68k stars 8.23k forks source link

[EDR Workflows] Get host details from CrowdStrike API #201345

Open tomsonpl opened 3 days ago

tomsonpl commented 3 days ago

Summary

This PR introduces functionality to fetch host details from the CrowdStrike API via our connector when no corresponding host document is found in Elasticsearch. This ensures we have a fallback mechanism to retrieve essential data directly from CrowdStrike, improving data availability and resilience in edge cases.

Key Changes

Why this is needed?

This change addresses gaps in host data when Elasticsearch lacks the necessary documents. By adding the CrowdStrike API as a fallback, we ensure seamless retrieval of agent status information, enhancing the reliability and accuracy of our system.

tomsonpl commented 3 days ago

/ci

tomsonpl commented 3 days ago

/ci

elasticmachine commented 3 days ago

Pinging @elastic/security-defend-workflows (Team:Defend Workflows)

elasticmachine commented 12 hours ago

:yellow_heart: Build succeeded, but was flaky

Failed CI Steps

Test Failures

Metrics [docs]

✅ unchanged

History

cc @tomsonpl