-
Notifications
You must be signed in to change notification settings - Fork 467
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[tanium] Initial Release for the Tanium #5072
Conversation
🌐 Coverage report
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
Is there a targeted release version for this integration? |
Hey @syedrafice - This integration will be available on Elastic stack versions greater than 7.17. and 8.x. |
Thank you @vinit-elastic. I should have clarified, what release will the integration get merged into the main integrations GitHub repo for the public to use? |
Hey @syedrafice - we're currently going through the PR review process and expect the Tanium integration to ship over the coming weeks. We don't have to wait for a stack release. Do you have a customer looking for the integration? We're shipping the integration as beta, and will be looking for early feedback if you have a user in mind. |
As discussed on the weekly meeting, feel free to add the dynamic template as well, according to: #5055 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
From what I can see its ready, but its quite a heavy integration, especially the threat datastream. A bit unsure how much we can see from a simple review.
I will leave it here for a little to see if anyone else have more comments.
...tanium/data_stream/threat_response/_dev/test/pipeline/test-threat-response.log-expected.json
Show resolved
Hide resolved
Since this includes proper testing, and has been tested against a live instance of the actual product, I will decide to merge. |
Package tanium - 0.1.0 containing this change is available at https://epr.elastic.co/search?package=tanium |
* Initial Release for the Tanium * Update the changelog entry * Add new threat response data stream * Add dynamic mapping * Change as per the review comments
* Initial Release for the Tanium * Update the changelog entry * Add new threat response data stream * Add dynamic mapping * Change as per the review comments
What does this PR do?
Note: This integration supports 6 data streams. Out of Which, theThreat Response
data stream is developed and tested with sample data. However, the other 5 data streams are developed and tested against the live data.Integration release checklist
This checklist is intended for integrations maintainers to ensure consistency
when creating or updating a Package, Module or Dataset for an Integration.
All changes
New Package
Dashboards changes
Log dataset changes
How to test this PR locally
Screenshots