Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
48 commits
Select commit Hold shift + click to select a range
f258ccb
[fortinet_forticlient] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
6d887c7
[fortinet_fortiedr] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
4d65b78
[fortinet_fortigate] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
f84ba2a
[fortinet_fortimail] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
41dfb86
[fortinet_fortimanager] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
2dccd56
[gcp_pubsub] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
8504c1e
[github] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
85dd0b4
[google_cloud_storage] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
1e01289
[google_scc] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
9a8230e
[google_workspace] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
429ed01
[hashicorp_vault] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
72f96fa
[hid_bravura_monitor] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
4dc4313
[http_endpoint] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
64905d0
[httpjson] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
bc37e4b
[imperva] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
664633c
[infoblox_bloxone_ddi] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
3e2498a
[infoblox_nios] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
02c5833
[iptables] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
8f5b57e
[jamf_compliance_reporter] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
c078fdd
[jumpcloud] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
a32a726
[juniper_srx] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
d6972cd
[keycloak] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
0ec7879
[lastpass] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
751ab63
[lyve_cloud] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
4b0c2bd
[m365_defender] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
ba63c4d
[mattermost] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
388bb85
[microsoft_defender_cloud] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
74e75f5
[microsoft_defender_endpoint] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
7199e0f
[microsoft_dhcp] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
3da1d85
[microsoft_exchange_online_message_trace] - change to ECS version git…
chemamartinez Nov 8, 2023
c15470e
[mimecast] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
c464d17
[modsecurity] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
0f26cc1
[mysql_enterprise] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
e6c99cf
[netflow] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
8848bc8
[netscout] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
88f93a3
[netskope] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
f18e030
[network_traffic] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
3ebfe72
[o365] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
3a597a3
[okta] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
352aaea
[osquery] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
9999925
[panw] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
44a5f1a
[panw_cortex_xdr] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
b4772ae
[pfsense] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
324e14b
[ping_one] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
66899fa
[prisma_cloud] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
1680efb
[proofpoint_tap] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
b5e1b7e
[pulse_connect_secure] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
f46f4dc
[qnap_nas] - change to ECS version git@v8.11.0
chemamartinez Nov 8, 2023
File filter

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion packages/fortinet_forticlient/_dev/build/build.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
dependencies:
ecs:
reference: "git@v8.10.0"
reference: "git@v8.11.0"
5 changes: 5 additions & 0 deletions packages/fortinet_forticlient/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: 1.10.0
changes:
- description: ECS version updated to 8.11.0.
type: enhancement
link: https://github.com/elastic/integrations/pull/8434
- version: 1.9.0
changes:
- description: ECS version updated to 8.10.0.
Expand Down

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ description: Pipeline for Fortinet FortiClient Endpoint Security
processors:
- set:
field: ecs.version
value: '8.10.0'
value: '8.11.0'
- set:
field: observer.vendor
value: Fortinet
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@
"port": 3994
},
"ecs": {
"version": "8.10.0"
"version": "8.11.0"
},
"elastic_agent": {
"id": "4e3f135a-d5f9-40b6-ae01-2c834ecbead0",
Expand Down
2 changes: 1 addition & 1 deletion packages/fortinet_forticlient/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ An example event for `log` looks as following:
"port": 3994
},
"ecs": {
"version": "8.10.0"
"version": "8.11.0"
},
"elastic_agent": {
"id": "4e3f135a-d5f9-40b6-ae01-2c834ecbead0",
Expand Down
2 changes: 1 addition & 1 deletion packages/fortinet_forticlient/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: fortinet_forticlient
title: Fortinet FortiClient Logs
version: "1.9.0"
version: "1.10.0"
description: Collect logs from Fortinet FortiClient instances with Elastic Agent.
type: integration
format_version: 2.7.0
Expand Down
2 changes: 1 addition & 1 deletion packages/fortinet_fortiedr/_dev/build/build.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
dependencies:
ecs:
reference: "git@v8.10.0"
reference: "git@v8.11.0"
5 changes: 5 additions & 0 deletions packages/fortinet_fortiedr/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: 1.14.0
changes:
- description: ECS version updated to 8.11.0.
type: enhancement
link: https://github.com/elastic/integrations/pull/8434
- version: "1.13.0"
changes:
- description: Improve 'event.original' check to avoid errors if set.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,14 +3,14 @@
{
"@timestamp": "2019-09-18T06:42:18.000Z",
"ecs": {
"version": "8.10.0"
"version": "8.11.0"
},
"event": {
"action": "blocked",
"category": "malware",
"end": "2019-09-18T02:42:18.000Z",
"id": "458478",
"original": "\u003c133\u003e1 2019-09-18T06:42:18.000Z 1.1.1.1 enSilo - - - Organization: Demo;Organization ID: 156646;Event ID: 458478; Raw Data ID: 1270886879;Device Name: WIN10-VICTIM;Operating System: Windows 10 Pro N; Process Name: svchost.exe;Process Path: \\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe; Process Type: 64bit;Severity: Critical;Classification: Suspicious;Destination: File Creation; First Seen: 18-Sep-2019, 02:42:18;Last Seen: 18-Sep-2019, 02:42:18;Action: Blocked;Count: 1; Certificate: yes;Rules List: File Encryptor - Suspicious file modification;Users: WIN10-VICTIM\\U; MAC Address: 00-0C-29-D4-75-EC;Script: N/A;Script Path: N/A;Autonomous System: N/A;Country: N/A",
"original": "<133>1 2019-09-18T06:42:18.000Z 1.1.1.1 enSilo - - - Organization: Demo;Organization ID: 156646;Event ID: 458478; Raw Data ID: 1270886879;Device Name: WIN10-VICTIM;Operating System: Windows 10 Pro N; Process Name: svchost.exe;Process Path: \\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe; Process Type: 64bit;Severity: Critical;Classification: Suspicious;Destination: File Creation; First Seen: 18-Sep-2019, 02:42:18;Last Seen: 18-Sep-2019, 02:42:18;Action: Blocked;Count: 1; Certificate: yes;Rules List: File Encryptor - Suspicious file modification;Users: WIN10-VICTIM\\U; MAC Address: 00-0C-29-D4-75-EC;Script: N/A;Script Path: N/A;Autonomous System: N/A;Country: N/A",
"start": "2019-09-18T02:42:18.000Z"
},
"fortinet": {
Expand Down Expand Up @@ -92,14 +92,14 @@
{
"@timestamp": "2019-09-18T07:42:18.000Z",
"ecs": {
"version": "8.10.0"
"version": "8.11.0"
},
"event": {
"action": "blocked",
"category": "malware",
"end": "2019-09-18T02:42:18.000Z",
"id": "458478",
"original": "\u003c133\u003e1 2019-09-18T07:42:18.000Z 1.1.1.1 enSilo 8710 - - Organization: Demo;Organization ID: 156646;Event ID: 458478; Raw Data ID: 1270886879;Device Name: WIN10-VICTIM;Operating System: Windows 10 Pro N; Process Name: svchost.exe;Process Path: \\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe; Process Type: 64bit;Severity: Critical;Classification: Suspicious;Destination: File Creation; First Seen: 18-Sep-2019, 02:42:18;Last Seen: 18-Sep-2019, 02:42:18;Action: Blocked;Count: 1; Certificate: yes;Rules List: File Encryptor - Suspicious file modification;Users: WIN10-VICTIM\\U; MAC Address: 00-0C-29-D4-75-EC;Script: N/A;Script Path: N/A;Autonomous System: N/A;Country: N/A",
"original": "<133>1 2019-09-18T07:42:18.000Z 1.1.1.1 enSilo 8710 - - Organization: Demo;Organization ID: 156646;Event ID: 458478; Raw Data ID: 1270886879;Device Name: WIN10-VICTIM;Operating System: Windows 10 Pro N; Process Name: svchost.exe;Process Path: \\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe; Process Type: 64bit;Severity: Critical;Classification: Suspicious;Destination: File Creation; First Seen: 18-Sep-2019, 02:42:18;Last Seen: 18-Sep-2019, 02:42:18;Action: Blocked;Count: 1; Certificate: yes;Rules List: File Encryptor - Suspicious file modification;Users: WIN10-VICTIM\\U; MAC Address: 00-0C-29-D4-75-EC;Script: N/A;Script Path: N/A;Autonomous System: N/A;Country: N/A",
"start": "2019-09-18T02:42:18.000Z"
},
"fortinet": {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ description: Pipeline for Fortinet FortiEDR Endpoint Detection and Response
processors:
- set:
field: ecs.version
value: '8.10.0'
value: '8.11.0'
- set:
field: observer.vendor
value: Fortinet
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@
"type": "logs"
},
"ecs": {
"version": "8.10.0"
"version": "8.11.0"
},
"elastic_agent": {
"id": "e2f57999-9659-45c8-a03c-c5bf85dc5124",
Expand All @@ -28,7 +28,7 @@
"end": "2019-09-18T02:42:18.000Z",
"id": "458478",
"ingested": "2022-08-26T07:24:21Z",
"original": "\u003c133\u003e1 2019-09-18T06:42:18.000Z 1.1.1.1 enSilo - - - Organization: Demo;Organization ID: 156646;Event ID: 458478; Raw Data ID: 1270886879;Device Name: WIN10-VICTIM;Operating System: Windows 10 Pro N; Process Name: svchost.exe;Process Path: \\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe; Process Type: 64bit;Severity: Critical;Classification: Suspicious;Destination: File Creation; First Seen: 18-Sep-2019, 02:42:18;Last Seen: 18-Sep-2019, 02:42:18;Action: Blocked;Count: 1; Certificate: yes;Rules List: File Encryptor - Suspicious file modification;Users: WIN10-VICTIM\\U; MAC Address: 00-0C-29-D4-75-EC;Script: N/A;Script Path: N/A;Autonomous System: N/A;Country: N/A",
"original": "<133>1 2019-09-18T06:42:18.000Z 1.1.1.1 enSilo - - - Organization: Demo;Organization ID: 156646;Event ID: 458478; Raw Data ID: 1270886879;Device Name: WIN10-VICTIM;Operating System: Windows 10 Pro N; Process Name: svchost.exe;Process Path: \\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe; Process Type: 64bit;Severity: Critical;Classification: Suspicious;Destination: File Creation; First Seen: 18-Sep-2019, 02:42:18;Last Seen: 18-Sep-2019, 02:42:18;Action: Blocked;Count: 1; Certificate: yes;Rules List: File Encryptor - Suspicious file modification;Users: WIN10-VICTIM\\U; MAC Address: 00-0C-29-D4-75-EC;Script: N/A;Script Path: N/A;Autonomous System: N/A;Country: N/A",
"start": "2019-09-18T02:42:18.000Z",
"timezone": "+00:00"
},
Expand Down Expand Up @@ -115,4 +115,4 @@
"user": {
"id": "WIN10-VICTIM\\U"
}
}
}
5 changes: 3 additions & 2 deletions packages/fortinet_fortiedr/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ An example event for `log` looks as following:
"type": "logs"
},
"ecs": {
"version": "8.10.0"
"version": "8.11.0"
},
"elastic_agent": {
"id": "e2f57999-9659-45c8-a03c-c5bf85dc5124",
Expand All @@ -53,7 +53,7 @@ An example event for `log` looks as following:
"end": "2019-09-18T02:42:18.000Z",
"id": "458478",
"ingested": "2022-08-26T07:24:21Z",
"original": "\u003c133\u003e1 2019-09-18T06:42:18.000Z 1.1.1.1 enSilo - - - Organization: Demo;Organization ID: 156646;Event ID: 458478; Raw Data ID: 1270886879;Device Name: WIN10-VICTIM;Operating System: Windows 10 Pro N; Process Name: svchost.exe;Process Path: \\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe; Process Type: 64bit;Severity: Critical;Classification: Suspicious;Destination: File Creation; First Seen: 18-Sep-2019, 02:42:18;Last Seen: 18-Sep-2019, 02:42:18;Action: Blocked;Count: 1; Certificate: yes;Rules List: File Encryptor - Suspicious file modification;Users: WIN10-VICTIM\\U; MAC Address: 00-0C-29-D4-75-EC;Script: N/A;Script Path: N/A;Autonomous System: N/A;Country: N/A",
"original": "<133>1 2019-09-18T06:42:18.000Z 1.1.1.1 enSilo - - - Organization: Demo;Organization ID: 156646;Event ID: 458478; Raw Data ID: 1270886879;Device Name: WIN10-VICTIM;Operating System: Windows 10 Pro N; Process Name: svchost.exe;Process Path: \\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe; Process Type: 64bit;Severity: Critical;Classification: Suspicious;Destination: File Creation; First Seen: 18-Sep-2019, 02:42:18;Last Seen: 18-Sep-2019, 02:42:18;Action: Blocked;Count: 1; Certificate: yes;Rules List: File Encryptor - Suspicious file modification;Users: WIN10-VICTIM\\U; MAC Address: 00-0C-29-D4-75-EC;Script: N/A;Script Path: N/A;Autonomous System: N/A;Country: N/A",
"start": "2019-09-18T02:42:18.000Z",
"timezone": "+00:00"
},
Expand Down Expand Up @@ -141,6 +141,7 @@ An example event for `log` looks as following:
"id": "WIN10-VICTIM\\U"
}
}

```

**Exported fields**
Expand Down
2 changes: 1 addition & 1 deletion packages/fortinet_fortiedr/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: fortinet_fortiedr
title: Fortinet FortiEDR Logs
version: "1.13.0"
version: "1.14.0"
description: Collect logs from Fortinet FortiEDR instances with Elastic Agent.
type: integration
format_version: "3.0.0"
Expand Down
2 changes: 1 addition & 1 deletion packages/fortinet_fortigate/_dev/build/build.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
dependencies:
ecs:
reference: "git@v8.10.0"
reference: "git@v8.11.0"
5 changes: 5 additions & 0 deletions packages/fortinet_fortigate/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: 1.22.0
changes:
- description: ECS version updated to 8.11.0.
type: enhancement
link: https://github.com/elastic/integrations/pull/8434
- version: "1.21.0"
changes:
- description: Add support for FortiOS 7.x.
Expand Down
Loading