[aws_securityhub] Initial release of AWS Security Hub#15932
[aws_securityhub] Initial release of AWS Security Hub#15932brijesh-elastic merged 12 commits intoelastic:mainfrom
Conversation
…issions (#137866) Adding logs-aws_securityhub.finding-* data stream indices to the kibana_system privileges. This is required for the latest transform to work. Related: elastic/integrations#15932
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
🚀 Benchmarks reportTo see the full report comment with |
...aws_securityhub/data_stream/finding/elasticsearch/ingest_pipeline/pipeline_object_device.yml
Outdated
Show resolved
Hide resolved
packages/aws_securityhub/data_stream/finding/elasticsearch/ingest_pipeline/default.yml
Show resolved
Hide resolved
packages/aws_securityhub/data_stream/finding/elasticsearch/ingest_pipeline/default.yml
Show resolved
Hide resolved
...ityhub/data_stream/finding/elasticsearch/ingest_pipeline/pipeline_object_vulnerabilities.yml
Show resolved
Hide resolved
packages/aws_securityhub/elasticsearch/transform/latest_cdr_vulnerabilities/fields/fields.yml
Show resolved
Hide resolved
packages/aws_securityhub/elasticsearch/transform/latest_findings/fields/fields.yml
Show resolved
Hide resolved
|
I think also that the document that forms the basis of the OCSF to ECS mapping should be made public and linked in the commit message. |
|
@kcreddy @brijesh-elastic Tested the env with data ingested. All good except missing |
It looks like I missed it. I’ll update this in the next commit, along with the cluster. |
packages/aws_securityhub/data_stream/finding/_dev/test/pipeline/test-common-config.yml
Outdated
Show resolved
Hide resolved
packages/aws_securityhub/data_stream/finding/elasticsearch/ingest_pipeline/default.yml
Outdated
Show resolved
Hide resolved
packages/aws_securityhub/data_stream/finding/elasticsearch/ingest_pipeline/default.yml
Show resolved
Hide resolved
@brijesh-elastic, spreadsheet permissions already there. You can share the link with reviewers, but Dan's point is on OCSF to ECS. |
Yes, I agree with making the OCSF to ECS mapping documents public, we can link it in the PR description |
maxcold
left a comment
There was a problem hiding this comment.
tested on provided environment, everything working as expected from our flows perspective
packages/aws_securityhub/data_stream/finding/elasticsearch/ingest_pipeline/default.yml
Show resolved
Hide resolved
kcreddy
left a comment
There was a problem hiding this comment.
LGTM. Thanks @brijesh-elastic
💚 Build Succeeded
History
|
|
Package aws_securityhub - 0.1.0 containing this change is available at https://epr.elastic.co/package/aws_securityhub/0.1.0/ |
Proposed commit message
Note
To Reviewers:
Checklist
changelog.ymlfile.How to test this PR locally
Related issues