- Notifications
You must be signed in to change notification settings - Fork 513
Closed
Labels
New IntegrationIssue or pull request for creating a new integration package.Issue or pull request for creating a new integration package.Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]release-pending
Description
Integration release checklist
The Elastic Security integration will ingest elastic security alerts from different es instances.
Integration name: Elastic Security
Data streams: alert
Input: CEL
We can collect the data using ES apis ingesting .internal.alerts-security.alerts-default-.. indices or kibana api https://www.elastic.co/docs/api/doc/kibana/operation/operation-searchalerts
Dashboard ideas:
- TO DO
All changes
- Change follows the contributing guidelines
- Supported versions of the monitoring target are documented
- Supported operating systems are documented (if applicable)
- Integration or System tests exist
- Documentation exists, useful guidelines to follow
- Fields follow ECS and naming conventions
- At least a manual test with ES / Kibana / Agent has been performed.
- Required Kibana version set to:
Metadata
Metadata
Assignees
Labels
New IntegrationIssue or pull request for creating a new integration package.Issue or pull request for creating a new integration package.Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]release-pending
